Vulnerabilities > CVE-2022-4937 - Missing Authorization vulnerability in Wclovers Frontend Manager for Woocommerce Along With Bookings Subscription Listings Compatible

047910
CVSS 8.8 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
LOW
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
HIGH
network
low complexity
wclovers
CWE-862

Summary

The WCFM Frontend Manager plugin for WordPress is vulnerable to unauthorized modification and access of data in versions up to, and including, 6.6.0 due to missing capability checks on various AJAX actions. This makes it possible for authenticated attackers, with minimal permissions such as subscribers, to perform a wide variety of actions such as modifying knowledge bases, modifying notices, modifying payments, managing vendors, capabilities, and so much more. There were hundreds of AJAX endpoints affected.

Vulnerable Configurations

Part Description Count
Application
Wclovers
236

Common Weakness Enumeration (CWE)