Record summary

CVE-2022-0814 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.

Description

The Ubigeo de Perú para Woocommerce WordPress plugin before 3.6.4 does not properly sanitise and escape some parameters before using them in SQL statements via various AJAX actions, some of which are available to unauthenticated users, leading to SQL Injections

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Affected products and versions

1
ProductSourceVersion rangeStatus

Ubigeo de Perú para Woocommerce y WordPress

CVE List3.6.4 to < 3.6.4affected

Nuclei templates

1
ProjectDiscoveryCRITICALUbigeo de Peru < 3.6.4 - SQL InjectionCVSS 9.8

The plugin does not properly sanitise and escape some parameters before using them in SQL statements via various AJAX actions, some of which are available to unauthenticated users, leading to SQL Injections.

Impact

Unauthenticated attackers can exploit SQL injection via AJAX actions to extract usernames and password hashes from the WordPress database.

Remediation

Fixed in version 3.6.4

WeaknessesCWE-89
Authorsr3Y3r53
Template tagscvecve2022wordpresswpscanwp-pluginsqliubigeo-peruunauthubigeo_de_peru_para_woocommerce_projectvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:a:ubigeo_de_peru_para_woocommerce_project:ubigeo_de_peru_para_woocommerce:*:*:*:*:*:wordpress:*:*
Shodan: http.html:/wp-content/plugins/ubigeo-peru/
FOFA: body=/wp-content/plugins/ubigeo-peru/

Source: ProjectDiscovery

References

2