CVE-2022-3915: Dokan < 3.7.6 - Unauthenticated SQLi
Published Dec 12, 2022
·Updated
The Dokan WordPress plugin before 3.7.6 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by unauthenticated users
Affected Software
2 affected components
weDevs Dokan Wordpress<3.7.6
Dokan Dokan WordPress<3.7.6
Event History
Dec 12, 2022
CVE Published
via MITRE·05:54 PM
Data Sourced
via MITRE·05:54 PM
DescriptionWeakness
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2022-3915?
The severity of CVE-2022-3915 is critical with a score of 9.8.
2
Which software versions are affected by CVE-2022-3915?
Dokan WordPress plugin versions up to and excluding 3.7.6 are affected by CVE-2022-3915.
3
What is the vulnerability description of CVE-2022-3915?
CVE-2022-3915 is a SQL injection vulnerability in the Dokan WordPress plugin before 3.7.6, which allows unauthenticated users to exploit it.
4
How can the SQL injection vulnerability in Dokan WordPress plugin be exploited?
Unauthenticated users can exploit the SQL injection vulnerability in Dokan WordPress plugin by not properly sanitizing and escaping a parameter before using it in a SQL statement.
5
How do I fix CVE-2022-3915 in the Dokan WordPress plugin?
To fix CVE-2022-3915, update to version 3.7.6 or above of the Dokan WordPress plugin.