S4E just found a medium-severity finding from leaked token-api key scanner
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Mar 4, 2024

CVE-2022-0814 Scanner

CVE-2022-0814 scanner - SQL Injection vulnerability in Ubigeo de Peru

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.6k
Times Used
continuous scan runs
5.5k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2022-0814
9.8
CVSS

The Ubigeo de Perú para Woocommerce WordPress plugin before 3.6.4 does not properly sanitise and escape some parameters before using them in SQL statements via various AJAX actions, some of which are available to unauthenticated users, leading to SQL Injections

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
Ubigeo de Perú para Woocommerce y WordPress
AFFECTED< 3.6.4SAFE ✓≥ 3.6.4
Updated Aug 22, 2026View on NVD →
Detail

Ubigeo de Peru para WooCommerce is a plugin designed for WooCommerce platforms, primarily used by e-commerce sites in Peru to manage geographic locations and addresses. It facilitates the categorization and identification of districts, provinces, and departments within Peru, streamlining the checkout process for customers by providing precise and localized address options. This plugin is essential for businesses that require detailed Peruvian geographic data to offer accurate shipping, taxation, and localized services. By integrating this plugin, WooCommerce sites enhance user experience, improve operational efficiency, and comply with local commerce regulations. It is a vital tool for e-commerce platforms looking to expand their reach within the Peruvian market.

The SQL Injection vulnerability within Ubigeo de Peru para WooCommerce is triggered via AJAX actions that improperly handle user inputs. Specifically, the 'rt_ubigeo_load_distritos_address' AJAX action fails to sanitize and escape the 'idProv' parameter, allowing attackers to inject malicious SQL code. This code is executed on the server, potentially compromising the database integrity and confidentiality. The vulnerability is exploitable through the 'admin-ajax.php' endpoint, a common entry point for AJAX requests in WordPress. This endpoint's misuse without proper security checks facilitates the execution of unauthorized SQL commands, highlighting the critical need for input validation.

If exploited, the SQL Injection vulnerability could have severe consequences, including unauthorized access to user accounts, disclosure of sensitive personal and financial information, alteration or deletion of data, and potential website defacement. Such breaches can result in significant reputational damage, loss of customer trust, and financial liabilities for the affected businesses. Moreover, it may serve as a gateway for further attacks, allowing attackers to escalate privileges or spread malware. The impact extends beyond data loss, threatening the integrity and availability of e-commerce operations on the WooCommerce platform.

By leveraging the S4E platform, users gain access to advanced security scanning tools capable of detecting vulnerabilities like the SQL Injection in Ubigeo de Peru para WooCommerce. Our platform offers detailed vulnerability reports, prioritized remediation guidance, and continuous monitoring services to safeguard your digital assets. Joining S4E empowers you with the knowledge and tools necessary to proactively address security weaknesses, ensuring the protection of your e-commerce site against evolving cyber threats. Enhance your cybersecurity posture and maintain the trust of your customers by securing your site with our comprehensive security solutions.

 

References

Solution Advice
  1. Immediately update the Ubigeo de Peru para WooCommerce plugin to version 3.6.4 or later.
  2. Regularly update all WordPress plugins and themes to their latest versions.
  3. Implement stringent input validation and sanitization practices to prevent SQL injection.
  4. Utilize a web application firewall (WAF) to detect and block malicious requests targeting known vulnerabilities.
  5. Conduct periodic security audits and vulnerability assessments to identify and mitigate potential security gaps in your web applications.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.