CVE Database /
CVE-2022-3915
CVE · Critical
CVE-2022-3915 — Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy [dokan-lite] < 3.7.6
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2022-3915
|
Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy [dokan-lite] < 3.7.6 |
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') |
Critical
9.8
|
< 3.7.6
|
3.7.6 |
2022-11-21 |
—
|
CVE-2022-3915
The Dokan plugin for WordPress versions up to and including 3.7.5 contains a SQL injection vulnerability in the 'user_ids' parameter of an AJAX action accessible to unauthenticated users. Because the parameter is not properly escaped or prepared before being used in database queries, attackers can inject additional SQL commands to extract sensitive data from the database. This flaw affects unprivileged and unauthenticated users alike, allowing arbitrary SQL query manipulation.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings