PT-2022-13436 · WordPress · Woocommerce Shipping Multiple Addresses

Cydave

·

Published

2022-05-02

·

Updated

2025-05-29

·

CVE-2022-0783

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Multiple Shipping Address Woocommerce WordPress plugin versions prior to 2.0
Description The issue concerns the improper sanitization and escaping of numerous parameters in SQL statements via certain AJAX actions. These actions are available to unauthenticated users, leading to potential unauthenticated SQL injections.
Recommendations For versions prior to 2.0, update to version 2.0 or later to resolve the issue. As a temporary workaround, consider restricting access to the AJAX actions available to unauthenticated users until a patch is applied.

Exploit

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2022-0783

Affected Products

Woocommerce Shipping Multiple Addresses