Vulnerabilities > CVE-2022-2382 - Missing Authorization vulnerability in Shapedplugin Product Slider for Woocommerce

047910
CVSS 4.3 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
LOW
Confidentiality impact
NONE
Integrity impact
LOW
Availability impact
NONE
network
low complexity
shapedplugin
CWE-862

Summary

The Product Slider for WooCommerce WordPress plugin before 2.5.7 has flawed CSRF checks and lack authorisation in some of its AJAX actions, allowing any authenticated users, such as subscriber to call them. One in particular could allow them to delete arbitrary blog options.

Vulnerable Configurations

Part Description Count
Application
Shapedplugin
56

Common Weakness Enumeration (CWE)