Record summary

CVE-2022-1057 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.

Description

The Pricing Deals for WooCommerce WordPress plugin through 2.0.2.02 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to an unauthenticated SQL injection

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Affected products and versions

1
ProductSourceVersion rangeStatus

Pricing Deals for WooCommerce

CVE List2.0.2.02 to ≤ 2.0.2.02affected

Nuclei templates

1
ProjectDiscoveryCRITICALWordPress Pricing Deals for WooCommerce <=2.0.2.02 - SQL InjectionCVSS 9.8

WordPress Pricing Deals for WooCommerce plugin through 2.0.2.02 contains a SQL injection vulnerability. The plugin does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action. An attacker can possibly obtain sensitive information, modify data, and/or execute unauthorized administrative operations in the context of the affected site.

Impact

Successful exploitation of this vulnerability could lead to unauthorized access to the WordPress database.

Remediation

Update to the latest version of the Pricing Deals for WooCommerce plugin (2.0.2.03 or higher) to fix the SQL Injection vulnerability.

WeaknessesCWE-89
Authorstheamanrawat
Template tagstime-based-sqlicvecve2022sqliwpscanwordpresswp-pluginwppricing-deals-for-woocommerceunauthvarktechvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:a:varktech:pricing_deals_for_woocommerce:*:*:*:*:*:wordpress:*:*

Source: ProjectDiscovery

References

2