Skip to main content

Vendor archive

letsrecover_project CVEs

Beta · best-effort

3 CVEs tagged to vendor letsrecover_project1 Critical, 2 High, 0 Medium, 0 Low, 0 Unrated.

CVE-2022-4357

Published Jan 2, 2023

The LetsRecover WordPress plugin before 1.2.0 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2022-4356

Published Jan 2, 2023

The LetsRecover WordPress plugin before 1.2.0 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2022-4355

Published Jan 2, 2023

The LetsRecover WordPress plugin before 1.2.0 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort
Showing 1-3 of 3 CVEsPage 1 of 1