PT-2022-24034 · WordPress · Booster For Woocommerce+2

Published

2022-11-21

·

Updated

2022-11-23

·

CVE-2022-3763

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions Booster for WooCommerce WordPress plugin versions prior to 5.6.7 Booster Plus for WooCommerce WordPress plugin versions prior to 5.6.5 Booster Elite for WooCommerce WordPress plugin versions prior to 1.1.7
Description The issue allows attackers to make a logged-in shop manager or admin delete files uploaded at the checkout via a CSRF attack, due to the lack of a CSRF check in place when deleting these files.
Recommendations For Booster for WooCommerce WordPress plugin versions prior to 5.6.7, update to version 5.6.7 or later. For Booster Plus for WooCommerce WordPress plugin versions prior to 5.6.5, update to version 5.6.5 or later. For Booster Elite for WooCommerce WordPress plugin versions prior to 1.1.7, update to version 1.1.7 or later.

Exploit

Fix

Related Identifiers

CVE-2022-3763

Affected Products

Booster Elite For Woocommerce
Booster Plus For Woocommerce
Booster For Woocommerce