Aller au contenu

Fiche vulnérabilité

CVE-2022-4017 : faille élevée booster booster elite woocommerce (CVSS 8.8)

Description

The Booster for WooCommerce WordPress plugin before 6.0.1, Booster Plus for WooCommerce WordPress plugin before 6.0.1, Booster Elite for WooCommerce WordPress plugin before 6.0.1 have either flawed CSRF checks or are missing them completely in numerous places, allowing attackers to make logged in users perform unwanted actions via CSRF attacks

En bref

Sévérité
Élevée (CVSS 8.8)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Exploitation active
Non signalée par la CISA
Publication
23 janv. 2023
Dernière mise à jour
17 juin 2026

Produits concernés

  • booster booster elite woocommerce
  • booster booster for woocommerce
  • booster booster plus woocommerce

Références

Rechercher une autre vulnérabilité dans la base CVE