CVE-2022-4997
8.6 HIGHPublished 2026-09-23 · Updated 2026-09-23
AI risk analysis
- Summary
- The flaw allows unauthenticated users to extract arbitrary data, including password hashes, by injecting a payment token into a SQL statement without proper sanitization.
- Exploitability
- Exploitation is relatively easy given the lack of authentication required, and the specific payment token can be crafted to extract sensitive data.
- Blast radius
- If exploited, the impact could be severe, as it allows unauthorized access to sensitive database information, potentially leading to data breaches.
- Detection
- No reliable host or network indicator is derivable from the published description.
- Prioritized remediation
- Upgrade to version 1.1.0 or later of the jet-form-builder-stripe-gateway WordPress plugin.
sql-injectiondata-exfiltrationwebwordpress
Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.
NVD description
The jet-form-builder-stripe-gateway WordPress plugin before 1.1.0 does not sanitise and escape a payment token before using it in a SQL statement, allowing unauthenticated users to extract arbitrary data from the database, including password hashes.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
Weaknesses
CWE-89
All references
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.
Related CVEs
- CRITICALCVE-2026-15360
- HIGHCVE-2026-15918
- MEDIUMCVE-2026-15941
- CRITICALCVE-2026-63713PoC
- CRITICALCVE-2023-54399
- CRITICALCVE-2023-54400PoC
- CRITICALCVE-2025-63564
- CRITICALCVE-2026-12718
Related by shared AI tags and CWE weakness class. Browse the full archive.