S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2022-0948 Scanner

Detects 'SQL Injection (SQLi)' vulnerability in Order Listener for WooCommerce plugin for WordPress affects v. before 3.2.2.

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.8k
Times Used
continuous scan runs
4.8k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2022-0948
9.8
CVSS

The Order Listener for WooCommerce WordPress plugin before 3.2.2 does not sanitise and escape the id parameter before using it in a SQL statement via a REST route available to unauthenticated users, leading to an SQL injection

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
Order Listener for WooCommerce – Play Sounds Instantly on New Orders
AFFECTED< 3.2.2SAFE ✓≥ 3.2.2
Updated Aug 22, 2026View on NVD →
Detail

The Order Listener for WooCommerce plugin is a highly popular WordPress add-on designed to offer seamless order handling for e-commerce websites. It works by listening in on incoming orders and sending out notifications to the designated recipient(s). This means that as soon as a customer places an order, the recipient is immediately notified, allowing them to act fast in processing and delivering the order. Additionally, this plugin can also be integrated with a variety of other third-party platforms, making it a versatile solution for e-commerce store owners.

One vulnerability that has been detected in the Order Listener for WooCommerce plugin is the CVE-2022-0948 vulnerability. This vulnerability centers on the plugin's failure to sanitize and escape the "id" parameter before using it in a SQL statement via a REST route that is available to unauthenticated users. Essentially, this means that hackers can take advantage of this loophole to inject malicious code into the order, leading to a breach in security. This vulnerability was first detected in version 3.2.1 and earlier of the plugin.

If this vulnerability is exploited, it can result in serious consequences for website owners. Hackers can use this loophole to access sensitive data, such as customer information, payment details, and even login credentials. This can lead to reputational damage, financial losses, and even legal consequences if it is found that the website owner was negligent in safeguarding their customers' data.

By using the s4e.io platform, website owners can easily and quickly learn about vulnerabilities in their digital assets. With its pro features, the platform provides an in-depth analysis of vulnerabilities and offers practical solutions for mitigating them. Additionally, the platform offers real-time alerts and notifications, allowing website owners to stay up-to-date with the latest security risks.

 

REFERENCES

Solution Advice

To protect against this vulnerability, here are a few precautions that website owners can take:

  • Update the plugin to version 3.2.2 or later. This version contains a fix for the CVE-2022-0948 vulnerability.
  • Use a web application firewall (WAF) to detect and block malicious traffic.
  • Regularly scan your website for vulnerabilities using a vulnerability scanner.
  • Only install plugins and themes from trusted sources.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.