Yotpo · Yotpo Reviews For Woocommerce · CVE-2022-2555
**Name of the Vulnerable Software and Affected Versions**
Yotpo Reviews for WooCommerce WordPress plugin versions 2.0.4 and earlier
**Description**
The issue concerns a lack of nonce check when updating settings, which could allow an attacker to make a logged-in admin change them via a CSRF attack. This could potentially lead to unauthorized changes in the plugin's settings.
**Recommendations**
For Yotpo Reviews for WooCommerce WordPress plugin versions 2.0.4 and earlier, update to a version that includes a nonce check for setting updates to prevent CSRF attacks.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.