Vulnerability Description
The Product Table for WooCommerce (wooproducttable) WordPress plugin before 3.1.2 does not have authorisation and CSRF checks in the wpt_admin_update_notice_option AJAX action (available to both unauthenticated and authenticated users), as well as does not validate the callback parameter, allowing unauthenticated attackers to call arbitrary functions with either none or one user controlled argument
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Codeastrology | Woo Product Table | < 3.1.2 |
Related Weaknesses (CWE)
References
- https://wpscan.com/vulnerability/04fe89b3-8ad1-482f-a96d-759d1d3a0dd5ExploitThird Party Advisory
- https://wpscan.com/vulnerability/04fe89b3-8ad1-482f-a96d-759d1d3a0dd5ExploitThird Party Advisory
FAQ
What is CVE-2022-1020?
CVE-2022-1020 is a vulnerability with a CVSS score of 9.8 (CRITICAL). The Product Table for WooCommerce (wooproducttable) WordPress plugin before 3.1.2 does not have authorisation and CSRF checks in the wpt_admin_update_notice_option AJAX action (available to both unaut...
How severe is CVE-2022-1020?
CVE-2022-1020 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2022-1020?
Check the references section above for vendor advisories and patch information. Affected products include: Codeastrology Woo Product Table.