CVE-2022-4016
Published on: Not Yet Published
Last Modified on: 12/15/2022 02:00:00 PM UTC
Certain versions of Booster For Woocommerce from Booster contain the following vulnerability:
The Booster for WooCommerce WordPress plugin before 5.6.7, Booster Plus for WooCommerce WordPress plugin before 5.6.6, Booster Elite for WooCommerce WordPress plugin before 1.1.8 does not properly check for CSRF when creating and deleting Customer roles, allowing attackers to make logged admins create and delete arbitrary custom roles via CSRF attacks
- CVE-2022-4016 has been assigned by
[email protected] to track the vulnerability - currently rated as MEDIUM severity.
- Affected Vendor/Software:
Unknown - Booster for WooCommerce version = 0
- Affected Vendor/Software:
Unknown - Booster Plus for WooCommerce version = 0
- Affected Vendor/Software:
Unknown - Booster Elite for WooCommerce version = 0
CVSS3 Score: 6.5 - MEDIUM
Attack Vector ⓘ |
Attack Complexity |
Privileges Required |
User Interaction |
---|---|---|---|
NETWORK | LOW | NONE | REQUIRED |
Scope | Confidentiality Impact |
Integrity Impact |
Availability Impact |
UNCHANGED | NONE | HIGH | NONE |
CVE References
Description | Tags ⓘ | Link |
---|---|---|
Booster for WooCommerce - Custom Role Creation/Deletion via CSRF WordPress Security Vulnerability | web.archive.org text/html Inactive LinkNot Archived |
![]() |
Related QID Numbers
- 150625 WordPress Booster for Woocommerce Plugin: Custom Role Creation/Deletion via CSRF Vulnerability (CVE-2022-4016)
Known Affected Configurations (CPE V2.3)
Type | Vendor | Product | Version | Update | Edition | Language |
---|---|---|---|---|---|---|
Application | Booster | Booster For Woocommerce | All | All | All | All |
Application | Booster | Booster For Woocommerce | All | All | All | All |
Application | Booster | Booster For Woocommerce | All | All | All | All |
- cpe:2.3:a:booster:booster_for_woocommerce:*:*:*:*:*:wordpress:*:*:
- cpe:2.3:a:booster:booster_for_woocommerce:*:*:*:*:elite:wordpress:*:*:
- cpe:2.3:a:booster:booster_for_woocommerce:*:*:*:*:plus:wordpress:*:*:
No vendor comments have been submitted for this CVE
Social Mentions
Source | Title | Posted (UTC) |
---|---|---|
![]() |
CVE-2022-4016 | 2022-12-12 19:43:30 |