CVE-2022-1014
WordPress vulnerability analysis and mitigation

Overview

The vulnerability CVE-2022-1014 affects the WP Contacts Manager WordPress plugin through version 2.2.4. The vulnerability was discovered and publicly disclosed on May 2, 2022. This security flaw exists in the plugin's handling of user-supplied POST data, which fails to implement proper sanitization before being used in SQL statements (WPScan, MITRE CVE).

Technical details

The vulnerability is classified as an SQL Injection (SQLI) vulnerability, falling under the OWASP Top 10 category A1: Injection and CWE-89. It has been assigned a critical CVSS score of 9.4, indicating its severe nature. The technical issue stems from inadequate sanitization of POST data that is subsequently interpolated into SQL statements. The vulnerability can be exploited through the WordPress admin-ajax.php endpoint with specific parameters (WPScan).

Impact

The SQL injection vulnerability allows attackers to execute arbitrary SQL queries against the WordPress database. This can potentially lead to unauthorized access to sensitive information, including user credentials, and could result in complete database compromise. The unauthenticated nature of the vulnerability makes it particularly severe as it can be exploited without requiring any prior authentication (WPScan).

Mitigation and workarounds

As of the vulnerability disclosure, there is no known fix available for this security issue. Users of the WP Contacts Manager plugin should consider disabling or removing the plugin until a security patch is released (WPScan).

Additional resources


SourceThis report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-14478HIGH7.5
  • demo-importer-plus
NoYesJan 17, 2026
CVE-2025-8615MEDIUM6.4
  • cubewp-framework
NoYesJan 17, 2026
CVE-2025-14078MEDIUM5.3
  • woocommerce-for-paygent-payment-main
NoYesJan 17, 2026
CVE-2025-12129MEDIUM5.3
  • cubewp-framework
NoYesJan 17, 2026
CVE-2026-0725MEDIUM4.4
  • integrate-dynamics-365-crm
NoYesJan 17, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management