Vulnerability Description
The Checkout Field Editor (Checkout Manager) for WooCommerce WordPress plugin before 1.8.0 unserializes user input provided via the settings, which could allow high privilege users such as admin to perform PHP Object Injection when a suitable gadget is present
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Themehigh | Checkout Field Editor For Woocommerce | < 1.8.0 |
References
- https://wpscan.com/vulnerability/0c9f22e0-1d46-4957-9ba5-5cca78861136ExploitThird Party Advisory
- https://wpscan.com/vulnerability/0c9f22e0-1d46-4957-9ba5-5cca78861136ExploitThird Party Advisory
FAQ
What is CVE-2022-3490?
CVE-2022-3490 is a vulnerability with a CVSS score of 7.2 (HIGH). The Checkout Field Editor (Checkout Manager) for WooCommerce WordPress plugin before 1.8.0 unserializes user input provided via the settings, which could allow high privilege users such as admin to pe...
How severe is CVE-2022-3490?
CVE-2022-3490 has been rated HIGH with a CVSS base score of 7.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-3490?
Check the references section above for vendor advisories and patch information. Affected products include: Themehigh Checkout Field Editor For Woocommerce.