CVE-2022-3763
Booster for WooCommerce - Checkout Files Deletion via CSRF
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
The Booster for WooCommerce WordPress plugin before 5.6.7, Booster Plus for WooCommerce WordPress plugin before 5.6.5, Booster Elite for WooCommerce WordPress plugin before 1.1.7 do not have CSRF check in place when deleting files uploaded at the checkout, allowing attackers to make a logged in shop manager or admin delete them via a CSRF attack
El complemento de WordPress Booster para WooCommerce anterior a 5.6.7, el complemento de WordPress Booster Plus para WooCommerce anterior a 5.6.5, el complemento de WordPress Booster Elite para WooCommerce anterior a 1.1.7 no tienen verificación CSRF al eliminar archivos cargados en la caja, lo que permite a los atacantes hacer que un administrador o administrador de la tienda que haya iniciado sesión los elimine mediante un ataque CSRF
The Booster Elite for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, but not including, 1.1.7. This is due to missing or incorrect nonce validation on an unknown function. This makes it possible for unauthenticated attackers to delete files uploaded during a check-out, granted they can trick a site administrator into performing an action such as clicking on a link.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2022-10-31 CVE Reserved
- 2022-10-31 CVE Published
- 2024-08-03 CVE Updated
- 2024-08-03 First Exploit
- 2024-12-17 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-352: Cross-Site Request Forgery (CSRF)
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|---|---|
https://wpscan.com/vulnerability/7ab15530-8321-487d-97a5-1469b51fcc3f | 2024-08-03 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Booster Search vendor "Booster" | Booster For Woocommerce Search vendor "Booster" for product "Booster For Woocommerce" | < 1.1.7 Search vendor "Booster" for product "Booster For Woocommerce" and version " < 1.1.7" | elite, wordpress |
Affected
| ||||||
Booster Search vendor "Booster" | Booster For Woocommerce Search vendor "Booster" for product "Booster For Woocommerce" | < 5.6.5 Search vendor "Booster" for product "Booster For Woocommerce" and version " < 5.6.5" | plus, wordpress |
Affected
| ||||||
Booster Search vendor "Booster" | Booster For Woocommerce Search vendor "Booster" for product "Booster For Woocommerce" | < 5.6.7 Search vendor "Booster" for product "Booster For Woocommerce" and version " < 5.6.7" | wordpress |
Affected
|