CVE-2022-36375
WordPress Tabs plugin <= 3.6.0 - Authenticated WordPress Options Change vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Authenticated (high role user) WordPress Options Change vulnerability in Biplob Adhikari's Tabs plugin <= 3.6.0 at WordPress.
Una Vulnerabilidad de cambio de opciones de WordPress Autenticado (usuario de alto rol) en el plugin Tabs de Biplob Adhikari versiones anteriores a 3.6.0 incluyéndola, en WordPress
The Tabs – Responsive Tabs with WooCommerce Product Tab Extension plugin for WordPress is vulnerable to arbitrary options updates in versions up to, and including, 3.6.8. This is due to a lack of validation on the settings supplied to the post_oxi_settings() function. This makes it possible for authenticated attackers, with administrative level permissions, to update arbitrary options on the WordPress site. This would only affect sites where the administrator has been restricted to not 'manage_options' or the administrator has allowed users with lower permissions to update the plugin's settings.
CVSS Scores
SSVC
- Decision:Track*
Timeline
- 2022-07-22 CVE Reserved
- 2022-07-25 CVE Published
- 2024-02-15 EPSS Updated
- 2025-02-20 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-264: Permissions, Privileges, and Access Controls
- CWE-639: Authorization Bypass Through User-Controlled Key
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
https://patchstack.com/database/vulnerability/vc-tabs/wordpress-tabs-plugin-3-6-0-authenticated-wordpress-options-change-vulnerability | Third Party Advisory | |
https://plugins.trac.wordpress.org/changeset/2646981 | Release Notes |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Oxilab Search vendor "Oxilab" | Responsive Tabs Search vendor "Oxilab" for product "Responsive Tabs" | <= 3.6.0 Search vendor "Oxilab" for product "Responsive Tabs" and version " <= 3.6.0" | wordpress |
Affected
|