/Vulnerability Library

Cryptocurrency Widgets Pack <= 1.8.1 - SQL Injection

CVE-2022-44588
Verified

Description

Cryptocurrency Widgets Pack Plugin <=1.8.1 for WordPress contains an unauthenticated SQL injection caused by unsanitized user input in database queries, letting attackers execute arbitrary SQL commands, exploit requires no authentication.

Severity

Critical

CVSS Score

9.8

Exploit Probability

2%

Published Date

February 21, 2026

Template Author

shivam kamboj

CVE-2022-44588.yaml
9.8Score

CVSS Metrics

CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVE ID:
cve-2022-44588
CWE ID:
cwe-89

References

https://nvd.nist.gov/vuln/detail/CVE-2022-44588https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/cryptocurrency-widgets-pack/cryptocurrency-widgets-pack-181-unauthenticated-sql-injection-2

Remediation Steps

Update to the latest version of the plugin where the vulnerability is fixed.