CRITICAL · 9.1

CVE-2022-30998

Multiple Authenticated (subscriber or higher user role) SQL Injection (SQLi) vulnerabilities in WooPlugins.co's Homepage Product Organizer for WooCommerce plugin <= 1.1 at WordPress.

Vulnerability Description

Multiple Authenticated (subscriber or higher user role) SQL Injection (SQLi) vulnerabilities in WooPlugins.co's Homepage Product Organizer for WooCommerce plugin <= 1.1 at WordPress.

CVSS Score

9.1

CRITICAL

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:L
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
CHANGED
Confidentiality
HIGH
Integrity
LOW
Availability
LOW

Affected Products

VendorProductVersions
Homepage Product Organizer For Woocommerce ProjectHomepage Product Organizer For Woocommerce<= 1.1

Related Weaknesses (CWE)

References

FAQ

What is CVE-2022-30998?

CVE-2022-30998 is a vulnerability with a CVSS score of 9.1 (CRITICAL). Multiple Authenticated (subscriber or higher user role) SQL Injection (SQLi) vulnerabilities in WooPlugins.co's Homepage Product Organizer for WooCommerce plugin <= 1.1 at WordPress.

How severe is CVE-2022-30998?

CVE-2022-30998 has been rated CRITICAL with a CVSS base score of 9.1/10. This is considered a critical vulnerability requiring immediate attention.

Is there a patch for CVE-2022-30998?

Check the references section above for vendor advisories and patch information. Affected products include: Homepage Product Organizer For Woocommerce Project Homepage Product Organizer For Woocommerce.