CVE-2022-0412: TI WooCommerce Wishlist < 1.40.1 - Unauthenticated Blind SQL Injection
The TI WooCommerce Wishlist WordPress plugin before 1.40.1, TI WooCommerce Wishlist Pro WordPress plugin before 1.40.1 do not sanitise and escape the itemid parameter before using it in a SQL statement via the wishlist/removeproduct REST endpoint, allowing unauthenticated attackers to perform SQL injection attacks
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-0412?
CVE-2022-0412 is rated as a high severity vulnerability due to its potential for SQL injection attacks.
How do I fix CVE-2022-0412?
To fix CVE-2022-0412, you should update the TI WooCommerce Wishlist and TI WooCommerce Wishlist Pro plugins to version 1.40.1 or later.
Who is affected by CVE-2022-0412?
CVE-2022-0412 affects users of the TI WooCommerce Wishlist and TI WooCommerce Wishlist Pro plugins versions prior to 1.40.1.
Can CVE-2022-0412 be exploited by authenticated users?
CVE-2022-0412 can be exploited by unauthenticated attackers, making it a critical risk.
What type of vulnerability is CVE-2022-0412?
CVE-2022-0412 is categorized as an SQL injection vulnerability.