CVE-2022-0478
The Event Manager and Tickets Selling for WooCommerce WordPress plugin before 3.5.8 does not validate and escape the post_author_gutenberg parameter before using it in a SQL statement when creating/editing events, which could allow users with a role as…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.54%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The Event Manager and Tickets Selling for WooCommerce WordPress plugin before 3.5.8 does not validate and escape the post_author_gutenberg parameter before using it in a SQL statement when creating/editing events, which could allow users with a role as low as contributor to perform SQL Injection attacks
- CVSS 3.1
- 8.8 HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 1.54% probability · 73th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-89
- Affected
- mage-people/event manager and tickets selling for woocommerce
- Source
- contact@wpscan.com
References
- https://plugins.trac.wordpress.org/changeset/2671860Patch, Third Party Advisory
- https://wpscan.com/vulnerability/d881d725-d06b-464f-a25e-88f41b1f431fExploit, Patch, Third Party Advisory
- https://plugins.trac.wordpress.org/changeset/2671860Patch, Third Party Advisory
- https://wpscan.com/vulnerability/d881d725-d06b-464f-a25e-88f41b1f431fExploit, Patch, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.