CVE-2022-2389
Summary
| CVE | CVE-2022-2389 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-08-22 15:15:00 UTC |
| Updated | 2024-01-04 15:17:00 UTC |
| Description | The Abandoned Cart Recovery for WooCommerce, Follow Up Emails, Newsletter Builder & Marketing Automation By Autonami WordPress plugin before 2.1.2 does not have authorisation and CSRF checks in one of its AJAX action, allowing any authenticated users, such as subscriber to create automations |
Risk And Classification
Problem Types: CWE-352 | CWE-862
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Buildwoofunnels | Autonami | All | All | All | All |
| Application | Funnelkit | Funnelkit Automations | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Automations By Autonami < 2.1.2 - Subscriber+ Automation Creation WordPress Security Vulnerability | MISC | wpscan.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
LEGACY: Krzysztof Zając
There are currently no legacy QID mappings associated with this CVE.