S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2022-0788 Scanner

CVE-2022-0788 scanner - SQL Injection (SQLi) vulnerability in WP Fundraising Donation and Crowdfunding Platform plugin for WordPress

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
3.2k
Times Used
continuous scan runs
5.5k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2022-0788
9.8
CVSS

The WP Fundraising Donation and Crowdfunding Platform WordPress plugin before 1.5.0 does not sanitise and escape a parameter before using it in a SQL statement via one of it's REST route, leading to an SQL injection exploitable by unauthenticated users

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
WP Fundraising Donation and Crowdfunding Platform
AFFECTED< 1.5.0SAFE ✓≥ 1.5.0
Updated Aug 22, 2026View on NVD →
Detail

WP Fundraising Donation and Crowdfunding Platform is a popular plugin used by WordPress users to raise funds and donations for various purposes such as charity, non-profit organizations, personal campaigns, and more. With this plugin, users can easily create campaigns, accept donations, and track the progress of their fundraising efforts. It is a convenient and reliable tool for those who seek to gather support for their projects and causes.

The recently discovered CVE-2022-0788 vulnerability is a critical security flaw in the WP Fundraising Donation and Crowdfunding Platform plugin before version 1.5.0. The plugin fails to sanitise and escape a parameter before using it in a SQL statement through its REST route, which can lead to SQL injection attacks. An attacker can exploit this vulnerability remotely without authentication, which means that even unauthenticated users can take advantage of the flaw to gain access to sensitive data or to manipulate the database.

When exploited, this vulnerability can have severe consequences. Attackers can steal data, modify the content of the website or database, inject malicious code, execute arbitrary commands, gain administrative access, and cause various forms of damage depending on their intentions. The consequences can range from minor issues to major security breaches that can put organizations, businesses, or individuals at risk of financial loss, reputation damage, legal action, and other serious consequences.

In conclusion, the WP Fundraising Donation and Crowdfunding Platform plugin is a valuable tool for fundraising and crowd sourcing for WordPress users. However, the recently detected CVE-2022-0788 vulnerability is a critical security flaw that can be exploited remotely by unauthenticated users. It can lead to severe consequences for users if ignored. Taking the precautions listed can help users protect their digital assets from SQL injection attempts. Furthermore, the pro features of s4e.io can help users identify any vulnerabilities in their digital assets and quickly patch them.

 

REFERENCES

Solution Advice

To protect against this vulnerability, users of WP Fundraising Donation and Crowdfunding Platform should take the following precautions:

  • Update the plugin to version 1.5.0 or later
  • Use an application firewall or security plugin that can detect and block SQL injection attempts
  • Limit the access of unauthenticated users to the REST API
  • Use strong and unique passwords for all accounts with access to the website and database
  • Regularly monitor and audit the website and database for signs of unauthorised access or malicious activity

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2022-0788 scanner - SQL Injection (SQLi) vulnerability in WP Fundraising Donation and Crowdfunding Platform plugin for WordPress | S4E