First published: Mon Jan 02 2023(Updated: )
The Visual Email Designer for WooCommerce WordPress plugin before 1.7.2 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by users with a role as low as author.
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
Smackcoders Visual Email Designer For Woocommerce | <1.7.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this issue is CVE-2022-3860.
The severity level of CVE-2022-3860 is high (8.8).
CVE-2022-3860 affects the Visual Email Designer for WooCommerce WordPress plugin before version 1.7.2.
The CWE ID associated with CVE-2022-3860 is CWE-89 (Improper Neutralization of Special Elements used in an SQL Command).
Yes, the fix for CVE-2022-3860 is to update the Visual Email Designer for WooCommerce WordPress plugin to version 1.7.2 or later.