ZeroHour

CVE-2022-3923

PoC
CVSS 3.1
4.3 medium
EPSS
<1%p40
Published
()
Modified
Description

The ActiveCampaign for WooCommerce WordPress plugin before 1.9.8 does not have authorisation check when cleaning up its error logs via an AJAX action, which could allow any authenticated users, such as subscriber to call it and remove error logs.

Vendors
activecampaign
Products
activecampaign for woocommerce
Ecosystems
WordPress, E-commerce
Weakness
CWE-862
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

In the news

No ingested article mentions this CVE yet.