S4E just found a medium-severity finding from cookies without secure attribute security misconfiguration scanner
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Mar 4, 2024

CVE-2022-4059 Scanner

CVE-2022-4059 scanner - SQL Injection vulnerability in Cryptocurrency Widgets Pack

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
3.2k
Times Used
continuous scan runs
4.4k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2022-4059
9.8
CVSScritical
Exploitable remotely over the internet · no authentication required.

The Cryptocurrency Widgets Pack WordPress plugin before 2.0 does not sanitise and escape some parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
Cryptocurrency Widgets Pack
AFFECTED< 2.0SAFE ✓≥ 2.0
Updated Aug 22, 2026View on NVD →
Detail

The Cryptocurrency Widgets Pack is a WordPress plugin developed by Blocksera that provides website owners with a suite of tools to display cryptocurrency-related information, such as prices, charts, and calculators. It is widely used by financial bloggers, cryptocurrency enthusiasts, and financial services websites to offer up-to-date crypto data to their visitors. The plugin supports multiple cryptocurrencies and integrates seamlessly with WordPress sites, enhancing user engagement by providing valuable market insights directly on web pages.

The SQL Injection vulnerability in versions of the Cryptocurrency Widgets Pack prior to 2.0 stems from the plugin's failure to properly sanitize and escape user inputs before incorporating them into SQL queries. This security flaw allows unauthenticated users to execute arbitrary SQL commands through the plugin’s AJAX actions, leading to potential unauthorized access to the website's database, data theft, and manipulation.

Specifically, the vulnerability is triggered through an AJAX action that does not adequately validate input parameters before using them in SQL statements. Attackers can exploit this by sending specially crafted requests to the 'admin-ajax.php' file, manipulating SQL queries to extract sensitive information from the database, alter database content, or perform other malicious actions without proper authentication.

Exploiting this vulnerability could have severe consequences, including the compromise of sensitive data such as user credentials and personal information stored in the WordPress database. It could also lead to unauthorized modifications to the website, further attacks on website users, and potentially full control over the affected website, posing significant risks to website integrity and user privacy.

By using the security scanning services provided by S4E, users can effectively identify and mitigate vulnerabilities like the SQL Injection in the Cryptocurrency Widgets Pack. Our platform offers detailed vulnerability assessments, prioritized remediation guidance, and continuous monitoring to protect digital assets against current and emerging threats. Joining S4E enables website owners to enhance their cybersecurity posture, ensuring their site remains secure, trustworthy, and compliant with industry standards.

 

References

Solution Advice
  1. Immediately update the Cryptocurrency Widgets Pack plugin to version 2.0 or higher.
  2. Regularly update all WordPress plugins and core installations to their latest versions to address known vulnerabilities.
  3. Implement a web application firewall (WAF) to detect and block SQL Injection attempts and other malicious activities.
  4. Conduct regular security audits and penetration testing to identify and rectify potential security issues.
  5. Educate website administrators and users about the importance of cybersecurity practices and the risks associated with SQL Injection attacks.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.