The Multiple Shipping Address Woocommerce plugin before 2.0 does not properly sanitize and escape numerous parameters before using them in SQL statements via some AJAX actions available to unauthenticated users, leading to unauthenticated SQL injections.
id: CVE-2022-0783
info:
name: Multiple Shipping Address Woocommerce < 2.0 - SQL Injection
autho
...