CVE-2022-1057 Information

Description

The Pricing Deals for WooCommerce WordPress plugin through 2.0.2.02 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users leading to an unauthenticated SQL injection

Reference

https://wpscan.com/vulnerability/7c33ffc3-84d1-4a0f-a837-794cdc3ad243

Share on: