ZeroHour

CVE-2022-0783

PoC
CVSS 3.1
9.8 critical
EPSS
8%p94
Published
()
Modified
Description

The Multiple Shipping Address Woocommerce WordPress plugin before 2.0 does not properly sanitise and escape numerous parameters before using them in SQL statements via some AJAX actions available to unauthenticated users, leading to unauthenticated SQL injections

Vendors
themehigh
Products
multiple shipping addresses for woocommerce
Ecosystems
WordPress, E-commerce
Weakness
CWE-89
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.