S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2022-0781 Scanner

CVE-2022-0781 scanner - SQL Injection vulnerability in Nirweb support plugin for Wordpress

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
3k
Times Used
continuous scan runs
4.8k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2022-0781
9.8
CVSS

The Nirweb support WordPress plugin before 2.8.2 does not sanitise and escape a parameter before using it in a SQL statement via an AJAX action (available to unauthenticated users), leading to an SQL injection

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
Nirweb support
AFFECTED< 2.8.2SAFE ✓≥ 2.8.2
Updated Aug 22, 2026View on NVD →
Detail

The Nirweb support plugin for WordPress is a tool designed to provide users with support for their websites. This plugin enables users to submit support requests, track tickets, and view support history, all from within the WordPress platform. The Nirweb support plugin is widely used and popular amongst WordPress users and website owners.

Recently, a vulnerability has been detected in the Nirweb support plugin, known as CVE-2022-0781. This vulnerability allows unauthenticated users to inject arbitrary SQL commands through a parameter that has not been sanitized or escaped before being used in an SQL statement via an AJAX action. This vulnerability could lead to unauthorized access to sensitive data, including usernames, passwords, or other confidential information.

If an attacker successfully exploits this vulnerability, they can gain access to the database and retrieve or modify stored information. This could allow them to gain control of the website and cause damage to its reputation. The possibilities are endless, depending on the motive of the attacker.

In conclusion, the Nirweb support plugin issue highlights the importance of staying up-to-date with software releases and keeping your website secure from vulnerabilities. s4e.io is an excellent platform that can quickly and easily help you identify vulnerabilities in your websites, including the Nirweb support plugin. Don't wait to become a victim of cyber-attacks. Protect yourself today!

 

REFERENCES

Solution Advice

To protect against the vulnerability identified in the Nirweb support plugin, the following precautions can be taken:

  • Update the plugin to its latest version, which contains the necessary patches to fix this vulnerability.
  • If updating is not feasible, remove the plugin altogether.
  • Monitor the logs and check them regularly for suspicious activity.
  • Harden the server by implementing strict access controls and a firewall.
  • Regularly backup your data.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.