Record summary

CVE-2022-0788 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.

Description

The WP Fundraising Donation and Crowdfunding Platform WordPress plugin before 1.5.0 does not sanitise and escape a parameter before using it in a SQL statement via one of it's REST route, leading to an SQL injection exploitable by unauthenticated users

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Affected products and versions

1
ProductSourceVersion rangeStatus

WP Fundraising Donation and Crowdfunding Platform

CVE List1.5.0 to < 1.5.0affected

Nuclei templates

1
ProjectDiscoveryCRITICALWordPress WP Fundraising Donation and Crowdfunding Platform <1.5.0 - SQL InjectionCVSS 9.8

WordPress WP Fundraising Donation and Crowdfunding Platform plugin before 1.5.0 contains an unauthenticated SQL injection vulnerability. It does not sanitize and escape a parameter before using it in a SQL statement via a REST route. An attacker can possibly obtain sensitive information, modify data, and/or execute unauthorized administrative operations in the context of the affected site.

Impact

Successful exploitation of this vulnerability could allow an attacker to execute arbitrary SQL queries, potentially leading to unauthorized access, data leakage, or manipulation of the WordPress database.

Remediation

Update WP Fundraising Donation and Crowdfunding Platform to version 1.5.0 or later to mitigate the vulnerability.

WeaknessesCWE-89
Authorstheamanrawat
Template tagstime-based-sqlicvecve2022sqliwordpresswp-pluginwpwp-fundraising-donationunauthwpscanwpmetvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:a:wpmet:wp_fundraising_donation_and_crowdfunding_platform:*:*:*:*:*:wordpress:*:*

Source: ProjectDiscovery

References

2