Record summary

CVE-2022-44588 has a selected CVSS score of 9.9 (critical); EIP currently links 1 Nuclei template.

Description

Unauth. SQL Injection vulnerability in Cryptocurrency Widgets Pack Plugin <=1.8.1 on WordPress.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationNone
AutomatableYes
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Feb 20, 2025 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus

Default status: unaffected

CVE ListThrough 1.8.1affected

Nuclei templates

1
ProjectDiscoveryCRITICALCryptocurrency Widgets Pack <= 1.8.1 - SQL InjectionCVSS 9.8

Cryptocurrency Widgets Pack Plugin <=1.8.1 for WordPress contains an unauthenticated SQL injection caused by unsanitized user input in database queries, letting attackers execute arbitrary SQL commands, exploit requires no authentication.

Impact

Attackers can execute arbitrary SQL commands, potentially leading to data theft, modification, or deletion of sensitive information.

Remediation

Update to the latest version of the plugin where the vulnerability is fixed.

WeaknessesCWE-89
AuthorsShivam Kamboj
Template tagscvecve2022wordpresswpwp-pluginsqlicryptocurrency-widgets-packunauth
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
FOFA: body="wp-content/plugins/cryptocurrency-widgets-pack"

Source: ProjectDiscovery

References

2