S4E just found a critical-severity finding from cve-2024-42009 scanner
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2022-0412 Scanner

CVE-2022-0412 scanner - SQL Injection vulnerability in WooCommerce Wishlist plugin for Wordpress and pro version

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2k
Times Used
continuous scan runs
4.2k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2022-0412
9.8
CVSS

The TI WooCommerce Wishlist WordPress plugin before 1.40.1, TI WooCommerce Wishlist Pro WordPress plugin before 1.40.1 do not sanitise and escape the item_id parameter before using it in a SQL statement via the wishlist/remove_product REST endpoint, allowing unauthenticated attackers to perform SQL injection attacks

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
TI WooCommerce Wishlistby TemplateInvaders
AFFECTED< 1.40.1SAFE ✓≥ 1.40.1
TI WooCommerce Wishlist Proby TemplateInvaders
AFFECTED< 1.40.1SAFE ✓≥ 1.40.1
Updated Aug 22, 2026View on NVD →
Detail

The WooCommerce Wishlist plugin is a handy tool for online shoppers who often add items to their wishlist for future purchases. This plugin allows users to create a list of products that they might want to buy in the future. It is available as a free version as well as a pro version that comes with advanced features such as social sharing and email reminders.

Recently, a vulnerability detected in the TI WooCommerce Wishlist and TI WooCommerce Wishlist Pro plugins has raised concerns. The CVE-2022-0412 vulnerability refers to SQL injection attacks that can be carried out by exploiting the item_id parameter in the wishlist/remove_product REST endpoint. This vulnerability allows attackers to bypass authentication and execute unauthorized SQL queries.

If exploited, this vulnerability can lead to complete data loss, damage to the database and loss of personal information. Unauthenticated attackers can gain access to sensitive information such as customer data, login credentials, and transaction details. This can negatively impact an e-commerce business, reducing customer trust and hurting brand reputation.

In conclusion, the TI WooCommerce Wishlist and TI WooCommerce Wishlist Pro plugins have some vulnerabilities that could adversely affect e-commerce businesses. However, using a tool like the s4e.io platform can help website owners stay informed about such vulnerabilities. With advanced features like automatic vulnerability scanning, easy-to-read security reports, and personalized security recommendations, website owners can keep their digital assets safe from cyber-attacks.

 

REFERENCES

Solution Advice

To protect against this vulnerability, website owners can take the following precautions:

  • Update the TI WooCommerce Wishlist plugin and TI WooCommerce Wishlist Pro plugin to version 1.40.1 or higher.
  • Use a web application firewall (WAF) to block incoming malicious traffic.
  • Implement least privilege access controls to limit the level of access granted to users.
  • Follow secure coding practices such as input validation and parameterized queries.
  • Regularly scan the website for security vulnerabilities using reliable security tools.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.