CVE-2022-1057
Pricing Deals for WooCommerce <= 2.0.2.02 - Unauthenticated SQLi
Record summary
CVE-2022-1057 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.
Description
The Pricing Deals for WooCommerce WordPress plugin through 2.0.2.02 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to an unauthenticated SQL injection
Exploitation context
Available material
- Nuclei templates
- 1
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Pricing Deals for WooCommerce | CVE List | 2.0.2.02 to ≤ 2.0.2.02 | affected |
Nuclei templates
1ProjectDiscoveryCRITICALWordPress Pricing Deals for WooCommerce <=2.0.2.02 - SQL InjectionCVSS 9.8
WordPress Pricing Deals for WooCommerce plugin through 2.0.2.02 contains a SQL injection vulnerability. The plugin does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action. An attacker can possibly obtain sensitive information, modify data, and/or execute unauthorized administrative operations in the context of the affected site.
Impact
Successful exploitation of this vulnerability could lead to unauthorized access to the WordPress database.
Remediation
Update to the latest version of the Pricing Deals for WooCommerce plugin (2.0.2.03 or higher) to fix the SQL Injection vulnerability.
Source: ProjectDiscovery