CVE Vulnerabilities

CVE-2022-4426

Published: Jan 09, 2023 | Modified: Apr 09, 2025
CVSS 3.x
4.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

The Mautic Integration for WooCommerce WordPress plugin before 1.0.3 does not have proper CSRF check when updating settings, and does not ensure that the options to be updated belong to the plugin, allowing attackers to make a logged in admin change arbitrary blog options via a CSRF attack.

Affected Software

NameVendorStart VersionEnd Version
Mautic_integration_for_woocommerceWpswings*1.0.3 (excluding)

References