CVE-2022-0775

T

he WooCommerce WordPress plugin before 6.2.1 does not have proper authorisation check when deleting reviews, which could allow any authenticated users, such as subscriber to delete arbitrary comment

Configurations

Configuration 1 (hide)

cpe:2.3:a:woocommerce:woocommerce:*:*:*:*:*:wordpress:*:*

History

21 Nov 2024, 06:39

Type Values Removed Values Added
References () https://developer.woocommerce.com/2022/02/22/woocommerce-6-2-1-security-fix/ - Release Notes () https://developer.woocommerce.com/2022/02/22/woocommerce-6-2-1-security-fix/ - Release Notes
References () https://plugins.trac.wordpress.org/changeset/2683324 - Patch () https://plugins.trac.wordpress.org/changeset/2683324 - Patch
References () https://wpscan.com/vulnerability/b76dbf37-a0a2-48cf-bd85-3ebbc2f394dd/ - Exploit, Third Party Advisory () https://wpscan.com/vulnerability/b76dbf37-a0a2-48cf-bd85-3ebbc2f394dd/ - Exploit, Third Party Advisory

Information

Published : 2024-01-16 16:15

Updated : 2025-06-11 17:15


NVD link : CVE-2022-0775

Mitre link : CVE-2022-0775

CVE.ORG link : CVE-2022-0775


JSON object : View

Products Affected
CWE
CWE-863

Incorrect Authorization