CVE-2022-3860

The Visual Email Designer for WooCommerce WordPress plugin before 1.7.2 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by users with a role as low as author.
Configurations

Configuration 1 (hide)

cpe:2.3:a:smackcoders:visual_email_designer_for_woocommerce:*:*:*:*:*:wordpress:*:*

History

21 Nov 2024, 07:20

Type Values Removed Values Added
References () https://wpscan.com/vulnerability/d99ce21f-fbb6-429c-aa3b-19c4a5eb7557 - Exploit, Third Party Advisory () https://wpscan.com/vulnerability/d99ce21f-fbb6-429c-aa3b-19c4a5eb7557 - Exploit, Third Party Advisory
Summary
  • (es) El complemento Visual Email Designer for WooCommerce de WordPress anterior a 1.7.2 no sanitiza ni escapa adecuadamente un parámetro antes de usarlo en una declaración SQL, lo que genera una inyección de SQL explotable por usuarios con un rol tan bajo como el de autor.

07 Nov 2023, 03:51

Type Values Removed Values Added
CWE CWE-89

Information

Published : 2023-01-02 22:15

Updated : 2024-11-21 07:20


NVD link : CVE-2022-3860

Mitre link : CVE-2022-3860

CVE.ORG link : CVE-2022-3860


JSON object : View

Products Affected

smackcoders

  • visual_email_designer_for_woocommerce
CWE

No CWE.