PT-2022-22771 · WordPress · Role Based Pricing For Woocommerce

Published

2022-11-07

·

Updated

2022-11-09

·

CVE-2022-3537

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Role Based Pricing for WooCommerce WordPress plugin versions prior to 1.6.2
Description The issue allows any authenticated users, such as subscribers, to upload arbitrary files, including PHP, due to the lack of authorization, proper CSRF checks, and file validation.
Recommendations For versions prior to 1.6.2, update to version 1.6.2 or later to resolve the issue. As a temporary workaround, consider restricting file upload capabilities to only trusted users until the update can be applied.

Exploit

Fix

Unrestricted File Upload

CSRF

Weakness Enumeration

Related Identifiers

CVE-2022-3537

Affected Products

Role Based Pricing For Woocommerce