First published: Mon Mar 14 2022(Updated: )
The Event Manager and Tickets Selling for WooCommerce WordPress plugin before 3.5.8 does not validate and escape the post_author_gutenberg parameter before using it in a SQL statement when creating/editing events, which could allow users with a role as low as contributor to perform SQL Injection attacks
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
Mage-people Event Manager And Tickets Selling Plugin For Woocommerce | <3.5.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-0478 is a vulnerability in the Event Manager and Tickets Selling for WooCommerce WordPress plugin before version 3.5.8 that allows users with low roles to perform SQL injection attacks.
CVE-2022-0478 has a severity score of 8.8 (High).
The Event Manager and Tickets Selling for WooCommerce WordPress plugin versions up to but excluding 3.5.8 are affected.
The Common Vulnerabilities and Exposures (CVE) ID for this vulnerability is CVE-2022-0478.
To fix CVE-2022-0478, update the Event Manager and Tickets Selling for WooCommerce WordPress plugin to version 3.5.8 or later.