S4E just found a critical-severity finding from cve-2024-42009 scanner
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2022-0349 Scanner

CVE-2022-0349 scanner - SQL Injection (SQLi) vulnerability in NotificationX plugin for WordPress

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
3.1k
Times Used
continuous scan runs
4.3k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2022-0349
9.8
CVSS

The NotificationX WordPress plugin before 2.3.9 does not sanitise and escape the nx_id parameter before using it in a SQL statement, leading to an Unauthenticated Blind SQL Injection

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
NotificationX – Best FOMO, Social Proof, WooCommerce Sales Popup & Notification Bar Plugin With Elementor
AFFECTED< 2.3.9SAFE ✓≥ 2.3.9
Updated Aug 22, 2026View on NVD →
Detail

NotificationX is a WordPress plugin that enables users to create and display eye-catching notifications on their website. This plugin is widely used for various purposes, including increasing conversions, promoting sales, and building engagement with site visitors. NotificationX plugin provides numerous ways to customize notifications and choose where to display them, making it an excellent tool for website owners who are looking to enhance their online presence.

Recently, a critical vulnerability has been detected in NotificationX plugin identified as CVE-2022-0349. This security vulnerability allows an unauthenticated user to conduct Blind SQL injection attacks on the plugin by exploiting the "nx_id" parameter. As the plugin does not sanitize and escape this parameter before using it in SQL statements, it allows hackers to execute arbitrary SQL commands and access sensitive information.

An attacker who exploits the vulnerability can gain unauthorized access to a website's database, which may contain valuable personal and business data. This may include user credentials, credit card details, emails, and more. Moreover, the attacker can steal sensitive information from other websites hosted on the same server by using SQL injection, which can lead to significant losses for website owners.

In conclusion, it is crucial for website owners to keep their digital assets safe from security vulnerabilities. With the pro features of the s4e.io platform, gaining such information is quick and easy. This platform offers comprehensive security solutions designed to detect, prevent, and combat cyber threats. By using this platform, users can stay ahead of cybercriminals and protect their websites from potential attacks.

 

REFERENCES

Solution Advice

To protect against this vulnerability, website owners can take the following precautions:

  • Install the latest version of NotificationX plugin, which fixes the vulnerability.
  • Disable the NotificationX plugin until the latest version is installed.
  • Use a web application firewall (WAF) to filter and block malicious requests.
  • Monitor and review server logs regularly to identify any suspicious activities.
  • Conduct regular security audits and vulnerability assessments to identify security weaknesses before attackers exploit them.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.