Vulnerability Description
The Booster for WooCommerce WordPress plugin before 5.6.7, Booster Plus for WooCommerce WordPress plugin before 5.6.6, Booster Elite for WooCommerce WordPress plugin before 1.1.8 does not properly check for CSRF when creating and deleting Customer roles, allowing attackers to make logged admins create and delete arbitrary custom roles via CSRF attacks
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Booster | Booster For Woocommerce | < 1.1.8 |
References
- https://wpscan.com/vulnerability/9b77044c-fd3f-4e6f-a759-dcc3082dcbd6ExploitThird Party Advisory
- https://wpscan.com/vulnerability/9b77044c-fd3f-4e6f-a759-dcc3082dcbd6ExploitThird Party Advisory
FAQ
What is CVE-2022-4016?
CVE-2022-4016 is a vulnerability with a CVSS score of 6.5 (MEDIUM). The Booster for WooCommerce WordPress plugin before 5.6.7, Booster Plus for WooCommerce WordPress plugin before 5.6.6, Booster Elite for WooCommerce WordPress plugin before 1.1.8 does not properly che...
How severe is CVE-2022-4016?
CVE-2022-4016 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-4016?
Check the references section above for vendor advisories and patch information. Affected products include: Booster Booster For Woocommerce.