CVE Database
/

CVE-2022-4888

Back to search

CVE-2022-4888

Published: Jul 31, 2023

Modified: Oct 17, 2024

PUBLISHED

Description

The Checkout Fields Manager WordPress plugin before 1.0.2, Abandoned Cart Recovery WordPress plugin before 1.2.5, Custom Fields for WooCommerce WordPress plugin before 1.0.4, Custom Order Number WordPress plugin through 1.0.1, Custom Registration Forms Builder WordPress plugin before 1.0.2, Advanced Free Gifts WordPress plugin before 1.0.2, Gift Registry for WooCommerce WordPress plugin through 1.0.1, Image Watermark for WooCommerce WordPress plugin before 1.0.1, Order Approval for WooCommerce WordPress plugin before 1.1.0, Order Tracking for WooCommerce WordPress plugin before 1.0.2, Price Calculator for WooCommerce WordPress plugin through 1.0.3, Product Dynamic Pricing and Discounts WordPress plugin through 1.0.6, Product Labels and Stickers WordPress plugin through 1.0.1 have flawed CSRF checks in various places, which could allow attackers to make logged in users perform unwanted actions

VendorProductVersions

Unknown

Checkout Fields Manager

affected
0 - < 1.0.2

Unknown

Abandoned Cart Recovery

affected
0 - < 1.2.5

Unknown

Custom Fields for WooCommerce

affected
0 - < 1.0.4

Unknown

Custom Order Number

affected
0 - <= 1.0.1

Unknown

Custom Registration Forms Builder

affected
0 - < 1.0.2

Unknown

Advanced Free Gifts

affected
0 - < 1.0.2

Unknown

Gift Registry for WooCommerce

affected
0 - <= 1.0.1

Unknown

Image Watermark for WooCommerce

affected
0 - < 1.0.1

Unknown

Order Approval for WooCommerce

affected
0 - < 1.1.0

Unknown

Order Tracking for WooCommerce

affected
0 - < 1.0.2

Unknown

Price Calculator for WooCommerce

affected
0 - <= 1.0.3

Unknown

Product Dynamic Pricing and Discounts

affected
0 - <= 1.0.6

Unknown

Product Labels and Stickers

affected
0 - <= 1.0.1

References

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now