cleantalk
Vulnerabilities and Security Researches

TI WooCommerce Wishlist, CVE-2022-0412

CVE, Research URL

CVE-2022-0412

Published on
Feb 28, 2022
Research Description
The TI WooCommerce Wishlist WordPress plugin before 1.40.1, TI WooCommerce Wishlist Pro WordPress plugin before 1.40.1 do not sanitise and escape the item_id parameter before using it in a SQL statement via the wishlist/remove_product REST endpoint, allowing unauthenticated attackers to perform SQL injection attacks
Affected versions
Min -, max 1.21.12.
Status
vulnerable