ZeroHour

CVE-2022-4426

PoC
CVSS 3.1
4.3 medium
EPSS
<1%p23
Published
()
Modified
Description

The Mautic Integration for WooCommerce WordPress plugin before 1.0.3 does not have proper CSRF check when updating settings, and does not ensure that the options to be updated belong to the plugin, allowing attackers to make a logged in admin change arbitrary blog options via a CSRF attack.

Vendors
wpswings
Products
mautic integration for woocommerce
Ecosystems
WordPress, E-commerce
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

In the news

No ingested article mentions this CVE yet.