CVE Database
/

CVE-2022-0412

Back to search

CVE-2022-0412

Published: Feb 28, 2022

Modified: Aug 2, 2024

PUBLISHED

Description

The TI WooCommerce Wishlist WordPress plugin before 1.40.1, TI WooCommerce Wishlist Pro WordPress plugin before 1.40.1 do not sanitise and escape the item_id parameter before using it in a SQL statement via the wishlist/remove_product REST endpoint, allowing unauthenticated attackers to perform SQL injection attacks

VendorProductVersions

TemplateInvaders

TI WooCommerce Wishlist

affected
1.40.1 - < 1.40.1

TemplateInvaders

TI WooCommerce Wishlist Pro

affected
1.40.1 - < 1.40.1

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now