PT-2023-13760 · WordPress · Booster Plus For Woocommerce+2

Publicado

2023-01-23

·

Atualizado

2023-01-31

·

CVE-2022-4017

CVSS v3.1

8.8

Alta

VetorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Booster for WooCommerce WordPress plugin versions prior to 6.0.1 Booster Plus for WooCommerce WordPress plugin versions prior to 6.0.1 Booster Elite for WooCommerce WordPress plugin versions prior to 6.0.1
Description The issue is related to flawed or missing CSRF checks in numerous places, allowing attackers to make logged-in users perform unwanted actions via CSRF attacks.
Recommendations For Booster for WooCommerce WordPress plugin versions prior to 6.0.1, update to version 6.0.1 or later. For Booster Plus for WooCommerce WordPress plugin versions prior to 6.0.1, update to version 6.0.1 or later. For Booster Elite for WooCommerce WordPress plugin versions prior to 6.0.1, update to version 6.0.1 or later.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2022-4017

Produtos afetados

Booster Elite For Woocommerce
Booster Plus For Woocommerce
Booster For Woocommerce