Vulnerability Description
The Wholesale Market WordPress plugin before 2.2.2, Wholesale Market for WooCommerce WordPress plugin before 2.0.1 have a flawed CSRF check when updating their settings, which could allow attackers to make a logged in admin update them via a CSRF attack
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Cedcommerce | Wholesale Market | < 2.2.2 |
| Cedcommerce | Wholesale Market For Woocommerce | < 2.0.1 |
Related Weaknesses (CWE)
References
- https://wpscan.com/vulnerability/734dba0b-f550-4372-884a-d42f7b0c00c7/ExploitThird Party Advisory
FAQ
What is CVE-2022-4363?
CVE-2022-4363 is a vulnerability with a CVSS score of 6.5 (MEDIUM). The Wholesale Market WordPress plugin before 2.2.2, Wholesale Market for WooCommerce WordPress plugin before 2.0.1 have a flawed CSRF check when updating their settings, which could allow attackers to...
How severe is CVE-2022-4363?
CVE-2022-4363 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-4363?
Check the references section above for vendor advisories and patch information. Affected products include: Cedcommerce Wholesale Market, Cedcommerce Wholesale Market For Woocommerce.