Lucene search

K
cvelistWPScanCVELIST:CVE-2022-0783
HistoryMay 02, 2022 - 4:05 p.m.

CVE-2022-0783 Multiple Shipping Address Woocommerce < 2.0 - Unauthenticated SQLi

2022-05-0216:05:45
CWE-89
WPScan
www.cve.org
6
cve-2022-0783
woocommerce
sql injection
unauthenticated
wordpress

AI Score

9.9

Confidence

High

EPSS

0.002

Percentile

57.6%

The Multiple Shipping Address Woocommerce WordPress plugin before 2.0 does not properly sanitise and escape numerous parameters before using them in SQL statements via some AJAX actions available to unauthenticated users, leading to unauthenticated SQL injections

CNA Affected

[
  {
    "product": "Multiple Shipping Address Woocommerce",
    "vendor": "Unknown",
    "versions": [
      {
        "lessThan": "2.0",
        "status": "affected",
        "version": "2.0",
        "versionType": "custom"
      }
    ]
  }
]

AI Score

9.9

Confidence

High

EPSS

0.002

Percentile

57.6%

Related for CVELIST:CVE-2022-0783