CVE-2022-0420
The RegistrationMagic WordPress plugin before 5.0.2.2 does not sanitise and escape the rm_form_id parameter before using it in a SQL statement in the Automation admin dashboard, allowing high privilege users to perform SQL injection attacks
Date published : 2022-03-07
https://plugins.trac.wordpress.org/changeset/2672042
https://wpscan.com/vulnerability/056b5167-3cbc-47d1-9917-52a434796151
