NA

CVE-2022-4888

Published: 31/07/2023 Updated: 07/11/2023
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

The Checkout Fields Manager WordPress plugin prior to 1.0.2, Abandoned Cart Recovery WordPress plugin prior to 1.2.5, Custom Fields for WooCommerce WordPress plugin prior to 1.0.4, Custom Order Number WordPress plugin up to and including 1.0.1, Custom Registration Forms Builder WordPress plugin prior to 1.0.2, Advanced Free Gifts WordPress plugin prior to 1.0.2, Gift Registry for WooCommerce WordPress plugin up to and including 1.0.1, Image Watermark for WooCommerce WordPress plugin prior to 1.0.1, Order Approval for WooCommerce WordPress plugin prior to 1.1.0, Order Tracking for WooCommerce WordPress plugin prior to 1.0.2, Price Calculator for WooCommerce WordPress plugin up to and including 1.0.3, Product Dynamic Pricing and Discounts WordPress plugin up to and including 1.0.6, Product Labels and Stickers WordPress plugin up to and including 1.0.1 have flawed CSRF checks in various places, which could allow malicious users to make logged in users perform unwanted actions

Vulnerable Product Search on Vulmon Subscribe to Product

addify order tracking for woocommerce

addify order approval for woocommerce

addify image watermark for woocommerce

addify gift registry for woocommerce

addify advanced free gifts

addify custom registration forms builder

addify custom order number

addify custom fields for woocommerce

addify abandoned cart recovery

addify checkout fields manager