RULE(RULE ID:337954)

Rule General Information
Release Date: 2024-04-23
Rule Name: WordPress Plugin Youzify SQL Injection Vulnerability (CVE-2022-1950)
Severity:
CVE ID:
Rule Protection Details
Description: The Youzify WordPress plugin before 1.2.0 does not sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to an unauthenticated SQL injection
Impact: An attacker can inject arbitrary sql commands to view or change the database of the target by exploiting the vulnerability successfully.
Affected OS: Windows, Linux, Others
Reference: https://wpscan.com/vulnerability/4352283f-dd43-4827-b417-0c55d0f4637d
https://nvd.nist.gov/vuln/detail/CVE-2022-1950
https://cxsecurity.com/cveshow/CVE-2022-1950/
Solutions
Refer to the announcement or patch by the vendor: https://wpscan.com/vulnerability/4352283f-dd43-4827-b417-0c55d0f4637d