Vulnerability Description
The Five Minute Webshop WordPress plugin through 1.3.2 does not sanitise and escape the id parameter before using it in a SQL statement when editing a product via the admin dashboard, leading to an SQL Injection
CVSS Score
LOW
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Five Minute Webshop Project | Five Minute Webshop | <= 1.3.2 |
Related Weaknesses (CWE)
References
- https://bulletin.iese.de/post/five-minute-webshop_1-3-2_2ExploitThird Party Advisory
- https://wpscan.com/vulnerability/1a5ce0dd-6847-42e7-8d88-3b63053fab71Third Party Advisory
- https://bulletin.iese.de/post/five-minute-webshop_1-3-2_2ExploitThird Party Advisory
- https://wpscan.com/vulnerability/1a5ce0dd-6847-42e7-8d88-3b63053fab71Third Party Advisory
FAQ
What is CVE-2022-1686?
CVE-2022-1686 is a vulnerability with a CVSS score of 2.7 (LOW). The Five Minute Webshop WordPress plugin through 1.3.2 does not sanitise and escape the id parameter before using it in a SQL statement when editing a product via the admin dashboard, leading to an SQ...
How severe is CVE-2022-1686?
CVE-2022-1686 has been rated LOW with a CVSS base score of 2.7/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-1686?
Check the references section above for vendor advisories and patch information. Affected products include: Five Minute Webshop Project Five Minute Webshop.