← back
CVE-2022-0948observed exploitationCWE-89

Order Listener for WooCommerce < 3.2.2 - Unauthenticated SQLi

40Vexday Risk Score

Patch now. It exploitation observed by VulnCheck and has a working public exploit.

ssvc Actepss 9.9%
from disclosure to weapon
Published on NVDMay 9
VulnCheck+1400d
exploitation probability
9.9%top 5% of all CVEs
observed exploitation
yesVulnCheck
The Order Listener for WooCommerce WordPress plugin before 3.2.2 does not sanitise and escape the id parameter before using it in a SQL statement via a REST route available to unauthenticated users, leading to an SQL injection