CVE-2022-44588
WordPress Cryptocurrency Widgets Pack Plugin <=1.8.1 is vulnerable to SQL Injection
Record summary
CVE-2022-44588 has a selected CVSS score of 9.9 (critical); EIP currently links 1 Nuclei template.
Description
Unauth. SQL Injection vulnerability in Cryptocurrency Widgets Pack Plugin <=1.8.1 on WordPress.
Exploitation context
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Feb 20, 2025 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Cryptocurrency Widgets PackBrowse Blocksera / Cryptocurrency Widgets PackDefault status: unaffected | CVE List | Through 1.8.1 | affected |
Nuclei templates
1ProjectDiscoveryCRITICALCryptocurrency Widgets Pack <= 1.8.1 - SQL InjectionCVSS 9.8
Cryptocurrency Widgets Pack Plugin <=1.8.1 for WordPress contains an unauthenticated SQL injection caused by unsanitized user input in database queries, letting attackers execute arbitrary SQL commands, exploit requires no authentication.
Impact
Attackers can execute arbitrary SQL commands, potentially leading to data theft, modification, or deletion of sensitive information.
Remediation
Update to the latest version of the plugin where the vulnerability is fixed.
Source: ProjectDiscovery