S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2022-1057 Scanner

Detects 'SQL Injection (SQLi)' vulnerability in Pricing Deals for WooCommerce plugin for WordPress affects v. through 2.0.2.02.

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.5k
Times Used
continuous scan runs
4.6k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2022-1057
9.8
CVSS

The Pricing Deals for WooCommerce WordPress plugin through 2.0.2.02 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to an unauthenticated SQL injection

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
Pricing Deals for WooCommerce
2.0.2.02
Updated Aug 22, 2026View on NVD →
Detail

The Pricing Deals for WooCommerce plugin for WordPress is a tool used to provide pricing deals to customers on e-commerce websites. Its purpose is to allow online store owners to offer various deals such as discounts and promotional pricing options. This plugin is widely used by online store owners for its ability to increase sales by offering the customers greater incentives to make a purchase. With over 50,000 active installations, Pricing Deals for WooCommerce is a popular choice for many online store owners.

However, a vulnerability with the CVE-2022-1057 code has been detected in this product. This vulnerability involves the plugin's failure to properly sanitise and escape a parameter before using it in a SQL statement through an AJAX action. This allows unauthenticated users to exploit the vulnerability by injecting malicious SQL queries. The vulnerability could result in a data breach as the attacker can retrieve sensitive information from the website's database.

If exploited, this vulnerability can lead to significant damage. The attacker can gain access to sensitive customer information stored in the website's database, such as personal details, payment information, and purchase history. This can result in identity theft, financial loss, and damage to the website's reputation. Additionally, the attacker can also modify or delete data from the database, potentially causing a loss of important data.

Through the pro features of s4e.io platform, website owners can easily and quickly learn about vulnerabilities in their digital assets. The platform offers real-time vulnerability scanning and detection, providing a comprehensive view of all vulnerabilities across websites and assets. s4e.io is committed to providing top-notch security for websites and e-commerce stores so that website owners can reassure their customers about sensitive information protection.

 

REFERENCES

Solution Advice

To protect against this vulnerability, website owners can take the following precautions:

  • Immediately update the Pricing Deals for WooCommerce plugin to the latest version to patch the vulnerability.
  • Regularly update all plugins and themes to ensure they are functioning with the latest security features.
  • Monitor the website's logs for suspicious activity and implement a web application firewall to protect against SQL injection attacks.
  • Ensure that the website has a reliable backup system in place, in case of data loss or corruption from an attack.
  • Train employees and users on how to spot and report suspicious activity.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.