The Multiple Shipping Address Woocommerce WordPress plugin before 2.0 does not properly sanitise and escape numerous parameters before using them in SQL statements via some AJAX actions available to unauthenticated users, leading to unauthenticated SQL injections
References
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: WPScan

Published: 2022-05-02T16:05:45

Updated: 2022-05-02T16:05:45

Reserved: 2022-02-28T00:00:00


Link: CVE-2022-0783

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2022-05-02T16:15:08.573

Modified: 2022-05-16T16:53:46.297


Link: CVE-2022-0783

JSON object: View

cve-icon Redhat Information

No data.

CWE