ZeroHour

CVE-2022-2389

PoC
CVSS 3.1
4.3 medium
EPSS
<1%p29
Published
()
Modified
Description

The Abandoned Cart Recovery for WooCommerce, Follow Up Emails, Newsletter Builder & Marketing Automation By Autonami WordPress plugin before 2.1.2 does not have authorisation and CSRF checks in one of its AJAX action, allowing any authenticated users, such as subscriber to create automations

Vendors
funnelkit
Products
funnelkit automations
Ecosystems
WordPress, E-commerce
Weakness
CWE-352, CWE-862
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

In the news

No ingested article mentions this CVE yet.