S4E just found an informational finding from web sayfası erişilebilirlik kontrolü
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
CVE

CVE-2022-1692

9.8
CVSS
Description

The CP Image Store with Slideshow WordPress plugin before 1.0.68 does not sanitise and escape the ordering_by query parameter before using it in a SQL statement in pages where the [codepeople-image-store] is embed, allowing unauthenticated users to perform an SQL injection attack

Attack Vector
-
Privileges Req.
-
User Interaction
-
cp image store with slideshow
Updated Sep 18, 2026View on NVD →
S4E scanner

CP Image Store with Slideshow <= 1.0.67 - SQL Injection

The CP Image Store with Slideshow WordPress plugin before 1.0.68 does not sanitise and escape the ordering_by query parameter before using it in a SQL statement in pages where the [codepeople-image-store] is embed, allowing unauthenticated users to perform an SQL injection attack. References: https://wpscan.com/vulnerability/83bae80c-f583-4d89-8282-e6384bbc7571/ https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/cp-image-store/cp-image-store-with-slideshow-1067-unauthenticated-sql-injection https://nvd.nist.gov/vuln/detail/CVE-2022-1692 Remediation: Update to version 1.0.68 or later.

Used 3.1k times · 1 assets checked · url

CVE history: cp image store with slideshow

Predict next CVE date with AI

Monitor this CVE on your assets

S4E maps published CVEs to scanners and forecasts the next disclosure window for your stack.

Create a free account →