PT-2023-13715 · WordPress · Activecampaign For Woocommerce

Lana Codes

·

Published

2023-01-09

·

Updated

2023-07-21

·

CVE-2022-3923

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions ActiveCampaign for WooCommerce WordPress plugin versions prior to 1.9.8
Description The issue concerns a lack of authorization check when cleaning up error logs via an AJAX action. This could allow any authenticated users, such as subscribers, to call the action and remove error logs.
Recommendations For versions prior to 1.9.8, update to version 1.9.8 or later to resolve the issue. As a temporary workaround, consider restricting access to the AJAX action responsible for cleaning up error logs until a patch is applied.

Exploit

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2022-3923

Affected Products

Activecampaign For Woocommerce