CVE-2022-0775

Severity
4.3MEDIUM
EPSS
0.3%
top 43.31%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 16

Description

The WooCommerce WordPress plugin before 6.2.1 does not have proper authorisation check when deleting reviews, which could allow any authenticated users, such as subscriber to delete arbitrary comment

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:NExploitability: 2.8 | Impact: 1.4

Affected Packages2 packages

CVEListV5unknown/woocommerce< 6.2.1

Patches

🔴Vulnerability Details

2
GHSA
GHSA-hw3h-gc2r-whp8: The WooCommerce WordPress plugin before 62024-01-16
CVEList
WooCommerce < 6.2.1 - Subscriber+ Arbitrary Comment Deletion2024-01-16