S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2022-3768 Scanner

CVE-2022-3768 scanner - SQL Injection (SQLi) vulnerability in WPSmartContracts plugin for WordPress

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
3.5k
Times Used
continuous scan runs
5.9k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2022-3768
8.8
CVSShigh
Exploitable remotely over the internet · low-privilege account sufficient.

The WPSmartContracts WordPress plugin before 1.3.12 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by users with a role as low as author

Attack Vector
Network
Privileges Req.
Low
User Interaction
None
Affected
WPSmartContracts
AFFECTED< 1.3.12SAFE ✓≥ 1.3.12
Updated Aug 22, 2026View on NVD →
Detail

WPSmartContracts is a WordPress plugin which is used for organizing and managing smart contracts on the WordPress platform. It facilitates the language for creating smart contracts in WordPress and allows for the deployment of these contracts on a blockchain. Smart contracts are self-executing contracts with conditions written in code. They function as a way to automate and streamline legal contracts.

Recently, a critical vulnerability has been detected in the WPSmartContracts WordPress plugin. The vulnerability is identified as CVE-2022-3768. It exists due to the improper sanitization and escaping of a parameter which is passed to a SQL statement. This vulnerability can be exploited by anyone with a role as low as an author. An attacker could easily exploit this vulnerability to inject malicious code into the SQL statement, which can provide unauthorized access to the database.

Exploiting this vulnerability can lead to a range of disastrous consequences. An attacker can gain unauthorized access to the WordPress database, allowing them to obtain valuable information or even to modify the existing data. Furthermore, the attacker could use this access to launch further attacks or to cause significant damage to the WordPress website or blog.

In summary, the WPSmartContracts WordPress plugin is an essential tool for anyone interested in organizing and managing smart contracts. However, with the recent discovery of the CVE-2022-3768 vulnerability, WordPress website owners need to take the necessary steps to protect themselves against this vulnerability. By following the recommended precautions and utilizing the robust protection of s4e.io, users can safeguard their digital assets and stay protected against known and unknown threats.

 

REFERENCES

Solution Advice

Thankfully, there are some crucial precautions that can be taken to protect against this vulnerability. They include:

  • Always keeping your WordPress installation up-to-date
  • Installing and enabling a robust security plugin on your WordPress website 
  • Limiting user roles and permissions on your website
  • Never using weak passwords 
  • Running regular security audits on your website 

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2022-3768 scanner - SQL Injection (SQLi) vulnerability in WPSmartContracts plugin for WordPress | S4E