plugin

Ubigeo Peru Vulnerabilities

2 known security issues reported for the Ubigeo Peru WordPress plugin. Most recent disclosed May 9, 2022.

1 medium

Running Ubigeo Peru on your site? Check whether your installed version is affected.

Scan your site free

Ubigeo de Perú para Woocommerce y WordPress [ubigeo-peru] < 3.6.4

unknown

[en] The Ubigeo de Perú para Woocommerce WordPress plugin before 3.6.4 does not properly sanitise and escape some parameters before using them in SQL statements via various AJAX actions, some of which are available to unauthenticated users, leading to SQL Injections

Affected:
up to 3.6.4
Fixed in:
3.6.4
Disclosed:
May 9, 2022

CVE-2022-0814 on NVD →

Ubigeo de Perú para Woocommerce y WordPress <= 3.6.3 - Unauthenticated SQL Injection

medium

The Ubigeo de Perú para Woocommerce WordPress plugin before 3.6.4 does not properly sanitise and escape some parameters before using them in SQL statements via various AJAX actions, some of which are available to unauthenticated users, leading to SQL Injections

CVSS:
6.5
Affected:
up to 3.6.4
Fixed in:
3.6.4
Disclosed:
Apr 18, 2022

CVE-2022-0814 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database