VulnerabilityModified
CVE-2022-2555
The Yotpo Reviews for WooCommerce WordPress plugin through 2.0.4 lacks nonce check when updating its settings, which could allow attacker to make a logged in admin change them via a CSRF attack.
MEDIUM 6.5EPSS 0.43%
Does this matter?
Lower severity and a low EPSS score (0.43%). Track it; it rarely justifies an emergency change on its own.
Description
The Yotpo Reviews for WooCommerce WordPress plugin through 2.0.4 lacks nonce check when updating its settings, which could allow attacker to make a logged in admin change them via a CSRF attack.
- CVSS 3.1
- 6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
- EPSS
- 0.43% probability · 36th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-352
- Affected
- yotpo reviews for woocommerce project/yotpo reviews for woocommerce
- Source
- contact@wpscan.com
References
- https://wpscan.com/vulnerability/7ec9e493-bc48-4a5d-8c7e-34beaba892aeExploit, Third Party Advisory
- https://wpscan.com/vulnerability/7ec9e493-bc48-4a5d-8c7e-34beaba892aeExploit, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.