Record summary

CVE-2022-0783 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.

Description

The Multiple Shipping Address Woocommerce WordPress plugin before 2.0 does not properly sanitise and escape numerous parameters before using them in SQL statements via some AJAX actions available to unauthenticated users, leading to unauthenticated SQL injections

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Affected products and versions

1
ProductSourceVersion rangeStatus

Multiple Shipping Address Woocommerce

CVE List2.0 to < 2.0affected

Nuclei templates

1
ProjectDiscoveryHIGHMultiple Shipping Address Woocommerce < 2.0 - SQL InjectionCVSS 8.6

The Multiple Shipping Address Woocommerce plugin before 2.0 does not properly sanitize and escape numerous parameters before using them in SQL statements via some AJAX actions available to unauthenticated users, leading to unauthenticated SQL injections.

Impact

Unauthenticated attackers can execute time-based blind SQL injection to extract database contents, potentially exposing sensitive WooCommerce customer and order data.

Remediation

Update the Multiple Shipping Address Woocommerce plugin to version 2.0 or later.

WeaknessesCWE-89
Authorsritikchaddha
Template tagscvecve2022wordpresswpwp-pluginmultiple-shipping-address-woocommercesqlivuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:a:themehigh:multiple_shipping_addresses_for_woocommerce:*:*:*:*:*:*:*:*
FOFA: body="wp-content/plugins/multiple-shipping-address-woocommerce"

Source: ProjectDiscovery

References

2