PT-2022-23629 · WordPress · Wp Shop

Ptsfence

·

Published

2022-09-09

·

Updated

2023-07-21

·

CVE-2022-36793

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions WP Shop plugin versions 3.9.6 and earlier
Description The issue concerns Unauthenticated Plugin Settings Change & Data Deletion vulnerabilities. This allows for changes to plugin settings and deletion of data without proper authentication.
Recommendations For WP Shop plugin versions 3.9.6 and earlier, update to a version later than 3.9.6 to resolve the issue.

Fix

Weakness Enumeration

Related Identifiers

CVE-2022-36793

Affected Products

Wp Shop