CVE-2022-36284
WordPress Affiliate For WooCommerce premium plugin <= 4.7.0 - Authenticated IDOR vulnerability leading to PayPal email change
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Authenticated IDOR vulnerability in StoreApps Affiliate For WooCommerce premium plugin <= 4.7.0 at WordPress allows an attacker to change the PayPal email. WooCommerce PayPal Payments plugin (free) should be at least installed to get the extra input field on the user profile page.
Una vulnerabilidad de IDOR autenticado en el plugin StoreApps Affiliate For WooCommerce premium versiones anteriores a 4.7.0 incluyéndola, en WordPress permite a un atacante cambiar el correo electrónico de PayPal. El plugin WooCommerce PayPal Payments (gratuito) debe ser instalado al menos para obtener el campo de entrada extra en la página de perfil del usuario
This plugin Affiliate For WooCommerce premium for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 4.7.0. This makes it possible for attackers to change the PayPal email address that receives payments.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2022-07-22 CVE Reserved
- 2022-08-01 CVE Published
- 2024-02-22 EPSS Updated
- 2024-09-16 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-639: Authorization Bypass Through User-Controlled Key
CAPEC
References (2)
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Storeapps Search vendor "Storeapps" | Affiliate For Woocommerce Search vendor "Storeapps" for product "Affiliate For Woocommerce" | <= 4.7.0 Search vendor "Storeapps" for product "Affiliate For Woocommerce" and version " <= 4.7.0" | wordpress |
Affected
|