Multiple Authenticated (subscriber or higher user role) SQL Injection (SQLi) vulnerabilities in WooPlugins.co's Homepage Product Organizer for WooCommerce plugin <= 1.1 at WordPress.
References
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 07:03
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 9.1 |
References | () https://patchstack.com/database/vulnerability/homepage-product-organizer-for-woocommerce/wordpress-homepage-product-organizer-for-woocommerce-plugin-1-1-multiple-authenticated-sql-injection-sqli-vulnerabilities - Third Party Advisory | |
References | () https://wordpress.org/plugins/homepage-product-organizer-for-woocommerce/#description - Product, Third Party Advisory |
26 Jul 2022, 15:05
Type | Values Removed | Values Added |
---|---|---|
References | (CONFIRM) https://patchstack.com/database/vulnerability/homepage-product-organizer-for-woocommerce/wordpress-homepage-product-organizer-for-woocommerce-plugin-1-1-multiple-authenticated-sql-injection-sqli-vulnerabilities - Third Party Advisory | |
References | (CONFIRM) https://wordpress.org/plugins/homepage-product-organizer-for-woocommerce/#description - Product, Third Party Advisory | |
CPE | cpe:2.3:a:homepage_product_organizer_for_woocommerce_project:homepage_product_organizer_for_woocommerce:*:*:*:*:*:wordpress:*:* | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 8.8 |
22 Jul 2022, 17:18
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2022-07-22 17:15
Updated : 2024-11-21 07:03
NVD link : CVE-2022-30998
Mitre link : CVE-2022-30998
CVE.ORG link : CVE-2022-30998
JSON object : View
Products Affected
homepage_product_organizer_for_woocommerce_project
- homepage_product_organizer_for_woocommerce
CWE
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')