CVE-2022-0412
Last modified
CVE-2022-0412 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. The TI WooCommerce Wishlist WordPress plugin before 1.40.1, TI WooCommerce Wishlist Pro WordPress plugin before 1.40.1 do not sanitise and escape the item_id parameter before using it in a SQL statement via the wishlist/remove_product REST endpoint, allowing unauthenticated attackers to perform SQL injection attacks. EPSS estimates a 74.58% chance of exploitation in the next 30 days.
Description
The TI WooCommerce Wishlist WordPress plugin before 1.40.1, TI WooCommerce Wishlist Pro WordPress plugin before 1.40.1 do not sanitise and escape the item_id parameter before using it in a SQL statement via the wishlist/remove_product REST endpoint, allowing unauthenticated attackers to perform SQL injection attacks
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Templateinvaders | Ti Woocommerce Wishlist | < 1.40.1 |
References
- https://plugins.trac.wordpress.org/changeset/2668899Release Notes, Third Party Advisory
- https://wpscan.com/vulnerability/e984ba11-abeb-4ed4-9dad-0bfd539a9682Exploit, Third Party Advisory
- https://plugins.trac.wordpress.org/changeset/2668899Release Notes, Third Party Advisory
- https://wpscan.com/vulnerability/e984ba11-abeb-4ed4-9dad-0bfd539a9682Exploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-0412?
How severe is CVE-2022-0412?
How do I fix CVE-2022-0412?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2022
- CVE-2022-0406Improper Authorization in GitHub repository janeczku/calibre…4.3
- CVE-2022-0407Heap-based Buffer Overflow in GitHub repository vim/vim prio…7.8
- CVE-2022-0408Stack-based Buffer Overflow in GitHub repository vim/vim pri…7.8
- CVE-2022-0409Unrestricted Upload of File with Dangerous Type in Packagist…7.8
- CVE-2022-0410The WP Visitor Statistics (Real Time Traffic) WordPress plug…8.8
- CVE-2022-0411The Asgaros Forum WordPress plugin before 2.0.0 does not san…8.8
- CVE-2022-0413Use After Free in GitHub repository vim/vim prior to 8.2.7.8
- CVE-2022-0414Improper Validation of Specified Quantity in Input in Packag…4.3
- CVE-2022-0415Remote Command Execution in uploading repository file in Git…8.8
- CVE-2022-0417Heap-based Buffer Overflow GitHub repository vim/vim prior t…7.8
- CVE-2022-0418The Event List WordPress plugin before 0.8.8 does not saniti…4.8
- CVE-2022-0419NULL Pointer Dereference in GitHub repository radareorg/rada…5.5
Are you affected by CVE-2022-0412?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
