ZeroHour

CVE-2022-1020

PoC
CVSS 3.1
9.8 critical
EPSS
26%p98
Published
()
Modified
Description

The Product Table for WooCommerce (wooproducttable) WordPress plugin before 3.1.2 does not have authorisation and CSRF checks in the wpt_admin_update_notice_option AJAX action (available to both unauthenticated and authenticated users), as well as does not validate the callback parameter, allowing unauthenticated attackers to call arbitrary functions with either none or one user controlled argument

Vendors
codeastrology
Products
woo product table
Ecosystems
WordPress, E-commerce
Weakness
CWE-352, CWE-862
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.