TI WooCommerce Wishlist, CVE-2022-0412
- CVE, Research URL
- Home page URL
- Application
- Published on
- Feb 28, 2022
- Research Description
- The TI WooCommerce Wishlist WordPress plugin before 1.40.1, TI WooCommerce Wishlist Pro WordPress plugin before 1.40.1 do not sanitise and escape the item_id parameter before using it in a SQL statement via the wishlist/remove_product REST endpoint, allowing unauthenticated attackers to perform SQL injection attacks
- Affected versions
-
Min -, max 1.21.12.
- Status
-
vulnerable