CVE-2022-0948

CVE-2022-0948: Order Listener for WooCommerce < 3.2.2 - Unauthenticated SQLi

Vendor Unknown
Product Order Listener for WooCommerce – Play Sounds Instantly on New Orders
Weakness CWE-89 · SQLi
Published May 9, 2022
Last update August 2, 2024

CVSS base score

—

What the vulnerability does

01Description

The Order Listener for WooCommerce WordPress plugin before 3.2.2 does not sanitise and escape the id parameter before using it in a SQL statement via a REST route available to unauthenticated users, leading to an SQL injection

Key dates

02Disclosure timeline

May 9, 2022 CVE published
August 2, 2024 Record updated

Related vulnerabilities

04Related CVE