๐Ÿ” CVE Alert

CVE-2022-4290

HIGH 8.8

Cyr to Lat <= 3.5 - Authenticated SQL Injection

CVSS Score
8.8
EPSS Score
0.0%
EPSS Percentile
0th

The Cyr to Lat plugin for WordPress is vulnerable to authenticated SQL Injection via the 'ctl_sanitize_title' function in versions up to, and including, 3.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This potentially allows authenticated users with the ability to add or modify terms or tags to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. A partial patch became available in version 3.6 and the issue was fully patched in version 3.7.

CWE CWE-89
Vendor ivijanstefan
Product cyr to lat enhanced
Published Oct 20, 2023
Last Updated Apr 8, 2026
Stay Ahead of the Next One

Get instant alerts for ivijanstefan cyr to lat enhanced

Be the first to know when new high vulnerabilities affecting ivijanstefan cyr to lat enhanced are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

ivijanstefan / Cyr to Lat Enhanced
0 โ‰ค 3.5

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wordfence.com: https://www.wordfence.com/threat-intel/vulnerabilities/id/c9c29130-1b42-4edd-ad62-6f635e03ae31?source=cve plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/browser/cyr3lat/trunk/cyr-to-lat.php?rev=1117224#L69

Credits

Ramuel Gall