CVE-2022-4118

Severity CVSS v4.0:
Pending analysis
Type:
CWE-89 SQL Injection
Publication date:
08/05/2023
Last modified:
31/01/2025

Description

The Bitcoin / AltCoin Payment Gateway for WooCommerce & Multivendor store / shop WordPress plugin through 1.7.1 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by authenticated users

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:coinmarketstats:bitcoin_\/_altcoin_payment_gateway_for_woocommerce:*:*:*:*:*:wordpress:*:* 1.7.1 (including)