Cryptocurrency Widgets Pack Plugin <=1.8.1 for WordPress contains an unauthenticated SQL injection caused by unsanitized user input in database queries, letting attackers execute arbitrary SQL commands, exploit requires no authentication.
id: CVE-2022-44588
info:
name: Cryptocurrency Widgets Pack <= 1.8.1 - SQL Injection
author: Shi
...