CVE-2022-3860

CVE-2022-3860: Visual Email Designer for WooCommerce < 1.7.2 - Multiple Author+ SQLi

Vendor Unknown
Product Visual Email Designer for WooCommerce
Published January 2, 2023
Last update April 10, 2025

CVSS base score

What the vulnerability does

01Description

The Visual Email Designer for WooCommerce WordPress plugin before 1.7.2 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by users with a role as low as author.

Key dates

02Disclosure timeline

January 2, 2023 CVE published
April 10, 2025 Record updated