PT-2022-13164 · WordPress · Ti Woocommerce Wishlist
Krzysztof Zając
·
Published
2022-02-28
·
Updated
2024-03-20
·
CVE-2022-0412
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
TI WooCommerce Wishlist WordPress plugin versions prior to 1.40.1
TI WooCommerce Wishlist Pro WordPress plugin versions prior to 1.40.1
Description
The issue allows unauthenticated attackers to perform SQL injection attacks due to the lack of sanitization and escaping of the
item id parameter in SQL statements via the "wishlist/remove product" REST endpoint. This is a time-based SQL injection, and databases can be extracted using specific commands.Recommendations
For TI WooCommerce Wishlist WordPress plugin versions prior to 1.40.1, update to version 1.40.1 or later.
For TI WooCommerce Wishlist Pro WordPress plugin versions prior to 1.40.1, update to version 1.40.1 or later.
As a temporary workaround, consider restricting access to the "wishlist/remove product" REST endpoint until a patch is available.
Exploit
Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ti Woocommerce Wishlist