CVE
CVE-2022-0948
9.8
CVSS
Description
The Order Listener for WooCommerce WordPress plugin before 3.2.2 does not sanitise and escape the id parameter before using it in a SQL statement via a REST route available to unauthenticated users, leading to an SQL injection
Attack Vector
-
Privileges Req.
-
User Interaction
-
order listener for woocommerce – play sounds instantly on new orders
Updated Sep 26, 2026View on NVD →
This CVE is in S4E's catalog, but no public scanner is mapped to it yet.
CVE history: order listener for woocommerce – play sounds instantly on new orders
Predict next CVE date with AIMonitor this CVE on your assets
S4E maps published CVEs to scanners and forecasts the next disclosure window for your stack.
Create a free account →