Lucene search

K
cvelistWPScanCVELIST:CVE-2022-3537
HistoryNov 07, 2022 - 12:00 a.m.

CVE-2022-3537 Role Based Pricing for WooCommerce < 1.6.2 - Subscriber+ Arbitrary File Upload

2022-11-0700:00:00
CWE-434
CWE-352
WPScan
www.cve.org
2
vulnerability
woocommerce
wordpress
plugin
file upload
csrf checks

AI Score

9

Confidence

High

EPSS

0.001

Percentile

32.6%

The Role Based Pricing for WooCommerce WordPress plugin before 1.6.2 does not have authorisation and proper CSRF checks, and does not validate files to be uploaded, allowing any authenticated users like subscriber to upload arbitrary files, such as PHP

CNA Affected

[
  {
    "vendor": "Unknown",
    "product": "Role Based Pricing for WooCommerce",
    "versions": [
      {
        "version": "1.6.2",
        "status": "affected",
        "lessThan": "1.6.2",
        "versionType": "custom"
      }
    ]
  }
]

AI Score

9

Confidence

High

EPSS

0.001

Percentile

32.6%

Related for CVELIST:CVE-2022-3537