Record summary

CVE-2022-3481 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.

Description

The WooCommerce Dropshipping WordPress plugin before 4.4 does not properly sanitise and escape a parameter before using it in a SQL statement via a REST endpoint available to unauthenticated users, leading to a SQL injection

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Jul 21, 2025 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationPoC
AutomatableYes
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated May 1, 2025 · Source: CVE List

Affected products and versions

2
ProductSourceVersion rangeStatus

WooCommerce Dropshipping

Default status: unaffected

CVE ListBefore 4.4affected
VulnCheckVersion data not supplied

Nuclei templates

1
ProjectDiscoveryCRITICALNotificationX Dropshipping < 4.4 - SQL InjectionCVSS 4.3

The plugin does not properly sanitise and escape a parameter before using it in a SQL statement via a REST endpoint available to unauthenticated users, leading to a SQL injection

Impact

Unauthenticated attackers can exploit time-based SQL injection through the REST endpoint to extract sensitive WooCommerce data including customer information, order details, and payment records.

Remediation

Update NotificationX Dropshipping plugin to version 4.4 or later that properly sanitizes and escapes parameters in REST endpoints.

WeaknessesCWE-20
Authorsritikchaddha
Template tagscvecve2022wordpresswp-pluginwpsqliwoocommercenotificationxvkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
CPE: cpe:2.3:a:smartbear:swagger_ui:*:*:*:*:*:*:*:*
FOFA: body="/wp-content/plugins/woocommerce-dropshipping"

Source: ProjectDiscovery

References

2