← Back to browse · API

CVE-2022-3481

Severity
CRITICAL
CVSS
9.8
EPSS
0.03686
Risk score
40.49
CISA KEV
No
PoC
No
Published
2022-11-07
Modified
2025-05-01
First seen
2026-08-07
Aliases
EUVD-2022-42853, GHSA-M4WM-6GF3-2XQW
Products
OPMC:WooCommerce Dropshipping 0 <4.4
Sources
euvd EUVD-2022-42853

Description

The WooCommerce Dropshipping WordPress plugin before 4.4 does not properly sanitise and escape a parameter before using it in a SQL statement via a REST endpoint available to unauthenticated users, leading to a SQL injection

References