The plugin does not sanitise and escape some parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection.
id: CVE-2022-4059
info:
name: Cryptocurrency Widgets Pack < 2.0 - SQL Injection
author: r3Y3r53
...