CVE-2022-40702
WordPress Advanced Local Pickup for WooCommerce Plugin <= 1.5.2 is vulnerable to Broken Access Control
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Missing Authorization vulnerability in Zorem Advanced Local Pickup for WooCommerce.This issue affects Advanced Local Pickup for WooCommerce: from n/a through 1.5.2.
Vulnerabilidad de autorización faltante en Zorem Advanced Local Pickup for WooCommerce. Este problema afecta a Local Pickup for WooCommerce: desde n/a hasta 1.5.2.
The Advanced Local Pickup for WooCommerce for WordPress is vulnerable to unauthorized access of AJAX actions due to a missing capability check on the functions wclp_update_state_dropdown_fun, wclp_update_work_hours_list_fun, wclp_update_edit_location_form_fun, and wclp_apply_work_hours_fun in versions up to, and including, 1.5.2. This makes it possible for subscriber-level attackers to invoke these functions and change plugin settings.
CVSS Scores
SSVC
- Decision:Track
Timeline
- 2022-09-27 CVE Reserved
- 2023-03-28 CVE Published
- 2024-01-25 EPSS Updated
- 2024-08-03 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-862: Missing Authorization
CAPEC
References (1)
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Zorem Search vendor "Zorem" | Advanced Local Pickup For Woocommerce Search vendor "Zorem" for product "Advanced Local Pickup For Woocommerce" | <= 1.5.2 Search vendor "Zorem" for product "Advanced Local Pickup For Woocommerce" and version " <= 1.5.2" | wordpress |
Affected
|