CVE-2022-29410
Authenticated SQL Injection (SQLi) vulnerability in Mufeng’s Hermit 音乐播放器 plugin <= 3.1.6 on WordPress allows attackers with Subscriber or higher user roles to execute SQLi attack via (&ids). Date published : 2022-04-28 https://patchstack.com/database/vulnerability/hermit/wordpress-hermit-plugin-3-1-6-authenticated-sql-injection-sqli-vulnerability