CVE-2022-44588 CRITICAL

CVE-2022-44588: WordPress Cryptocurrency Widgets Pack Plugin <=1.8.1 is vulnerable to SQL Injection

Vendor Blocksera
Product Cryptocurrency Widgets Pack
Weakness CWE-89 · SQLi
Published December 15, 2022
Last update April 28, 2026

CVSS base score

9.9/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality High
Integrity Low

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:L

What the vulnerability does

01Description

Unauth. SQL Injection vulnerability in Cryptocurrency Widgets Pack Plugin <=1.8.1 on WordPress.

Explanation of Vulnerability in Simple Terms

02Summary

The Cryptocurrency Widgets Pack contains a SQL injection vulnerability that allows unauthenticated attackers to query the site's database directly. No user interaction is required. An attacker can extract sensitive data, modify database records, or disrupt site availability. The vulnerability affects all versions up to 1.8.1.

What an attacker can do

03Attacker Capabilities

Query or modify the site database and extract sensitive information without authentication.

Potential impact on your site

04Site Impact

Attackers can steal user data, modify content, or take the site offline without needing a login.

Conditions required to exploit

05Prerequisites

Network access only; no authentication or user interaction required.

Key dates

06Disclosure timeline

December 15, 2022 CVE published
April 28, 2026 Record updated

Related vulnerabilities

08Related CVE