CVE-2022-0783: Multiple Shipping Address Woocommerce < 2.0 - Unauthenticated SQLi
The Multiple Shipping Address Woocommerce WordPress plugin before 2.0 does not properly sanitise and escape numerous parameters before using them in SQL statements via some AJAX actions available to unauthenticated users, leading to unauthenticated SQL injections
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this vulnerability?
The vulnerability ID of this vulnerability is CVE-2022-0783.
What is the title of this vulnerability?
The title of this vulnerability is 'The Multiple Shipping Address Woocommerce WordPress plugin before 2.0 does not properly sanitise and escape numerous parameters before using them in SQL statements via some AJAX actions available to unauthenticated users, leading to unauthenticated SQL injections.'
What is the severity of CVE-2022-0783?
The severity of CVE-2022-0783 is critical with a severity value of 9.8.
What is the affected software of CVE-2022-0783?
The affected software of CVE-2022-0783 is the 'Themehigh Multiple Shipping Addresses For Woocommerce' plugin version up to, but not including, 2.0.0.
What is the CWE of CVE-2022-0783?
The CWE of CVE-2022-0783 is CWE-89.