Ubigeo de Perú para Woocommerce y WordPress [ubigeo-peru] < 3.6.4
unknown
[en] The Ubigeo de Perú para Woocommerce WordPress plugin before 3.6.4 does not properly sanitise and escape some parameters before using them in SQL statements via various AJAX actions, some of which are available to unauthenticated users, leading to SQL Injections
- Affected:
- up to 3.6.4
- Fixed in:
- 3.6.4
- Disclosed:
- May 9, 2022
CVE-2022-0814 on NVD →
Ubigeo de Perú para Woocommerce y WordPress <= 3.6.3 - Unauthenticated SQL Injection
medium
The Ubigeo de Perú para Woocommerce WordPress plugin before 3.6.4 does not properly sanitise and escape some parameters before using them in SQL statements via various AJAX actions, some of which are available to unauthenticated users, leading to SQL Injections
- CVSS:
- 6.5
- Affected:
- up to 3.6.4
- Fixed in:
- 3.6.4
- Disclosed:
- Apr 18, 2022
CVE-2022-0814 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database