← back
CVE-2022-2754CWE-89

Ketchup Restaurant Reservations <= 1.0.0 - Unauthenticated Blind SQLi

15Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackepss 38%
exploitation probability
38%top 2% of all CVEs
observed exploitation
nono source reports it
The Ketchup Restaurant Reservations WordPress plugin through 1.0.0 does not validate and escape some reservation parameters before using them in SQL statements, which could allow unauthenticated attackers to perform SQL Injection attacks