Fiche vulnérabilité
CVE-2022-3537 : faille élevée addify role based pricing for… (CVSS 8.8)
Description
The Role Based Pricing for WooCommerce WordPress plugin before 1.6.2 does not have authorisation and proper CSRF checks, and does not validate files to be uploaded, allowing any authenticated users like subscriber to upload arbitrary files, such as PHP
En bref
- Sévérité
- Élevée (CVSS 8.8)
- Vecteur CVSS
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Exploitation active
- Non signalée par la CISA
- Publication
- 7 nov. 2022
- Dernière mise à jour
- 17 juin 2026
Produits concernés
- addify role based pricing for woocommerce