CVE-2022-3860: Visual Email Designer for WooCommerce < 1.7.2 - Multiple Author+ SQLi
Published Jan 2, 2023
·Updated
The Visual Email Designer for WooCommerce WordPress plugin before 1.7.2 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by users with a role as low as author.
Affected Software
1 affected component
Smackcoders Visual Email Designer For Woocommerce Wordpress<1.7.2
Event History
Jan 2, 2023
CVE Published
via MITRE·09:53 PM
Data Sourced
via MITRE·09:53 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID of this issue?
The vulnerability ID of this issue is CVE-2022-3860.
2
What is the severity level of CVE-2022-3860?
The severity level of CVE-2022-3860 is high (8.8).
3
How does CVE-2022-3860 affect the Visual Email Designer for WooCommerce WordPress plugin?
CVE-2022-3860 affects the Visual Email Designer for WooCommerce WordPress plugin before version 1.7.2.
4
What is the CWE ID associated with CVE-2022-3860?
The CWE ID associated with CVE-2022-3860 is CWE-89 (Improper Neutralization of Special Elements used in an SQL Command).
5
Is there a fix available for CVE-2022-3860?
Yes, the fix for CVE-2022-3860 is to update the Visual Email Designer for WooCommerce WordPress plugin to version 1.7.2 or later.