CVE-2022-3860

CVE-2022-3860: Visual Email Designer for WooCommerce < 1.7.2 - Multiple Author+ SQLi

Vendor Unknown
Product Visual Email Designer for WooCommerce
Published January 2, 2023
Last update April 10, 2025

CVSS base score

—

What the vulnerability does

01Description

The Visual Email Designer for WooCommerce WordPress plugin before 1.7.2 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by users with a role as low as author.

Key dates

02Disclosure timeline

January 2, 2023 CVE published
April 10, 2025 Record updated