CVE-2022-0775
WooCommerce < 6.2.1 - Subscriber+ Arbitrary Comment Deletion
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
The WooCommerce WordPress plugin before 6.2.1 does not have proper authorisation check when deleting reviews, which could allow any authenticated users, such as subscriber to delete arbitrary comment
El complemento WooCommerce WordPress anterior a 6.2.1 no tiene una verificación de autorización adecuada al eliminar reseñas, lo que podría permitir a cualquier usuario autenticado, como un suscriptor, eliminar comentarios arbitrarios.
The WooCommerce plugin for WordPress is vulnerable to authorization bypass due to an insufficient capability check on the /wc/v2/products/ REST API in versions up to, and including, 6.2.0. This makes it possible for authenticated attackers with minimal permissions such as a subscriber to delete, edit, and read arbitrary comments and reviews.
CVSS Scores
SSVC
- Decision:Track*
Timeline
- 2022-02-22 CVE Published
- 2022-02-28 CVE Reserved
- 2024-01-24 EPSS Updated
- 2024-11-13 CVE Updated
- 2024-11-13 First Exploit
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-285: Improper Authorization
- CWE-863: Incorrect Authorization
CAPEC
References (3)
URL | Tag | Source |
---|---|---|
https://developer.woocommerce.com/2022/02/22/woocommerce-6-2-1-security-fix | Release Notes |
URL | Date | SRC |
---|---|---|
https://wpscan.com/vulnerability/b76dbf37-a0a2-48cf-bd85-3ebbc2f394dd | 2024-11-13 |
URL | Date | SRC |
---|---|---|
https://plugins.trac.wordpress.org/changeset/2683324 | 2024-01-19 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Woocommerce Search vendor "Woocommerce" | Woocommerce Search vendor "Woocommerce" for product "Woocommerce" | < 6.2.1 Search vendor "Woocommerce" for product "Woocommerce" and version " < 6.2.1" | wordpress |
Affected
|