4.3
CVSSv3

CVE-2022-3451

Published: 07/11/2022 Updated: 21/07/2023
CVSS v3 Base Score: 4.3 | Impact Score: 1.4 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

The Product Stock Manager WordPress plugin prior to 1.0.5 does not have authorisation and proper CSRF checks in multiple AJAX actions, allowing users with a role as low as subscriber to call them. One action in particular could allow to update arbitrary options

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

addify product stock manager