QID 150458

Date Published: 2022-01-27

QID 150458: WordPress Waitlist Woocommerce Plugin: CSRF Vulnerability (CVE-2022-0215)

Waitlist For Woocommerce is an WordPress plugin. Using this plugin, you can build a waiting list of people wanting the unavailable item, then notify customers automatically when products arrive.

In the installed version of the WordPress plugin, the "save_settings" function does not check for the "nonce", which could allow cross-site request forgery (CSRF) under some circumstances.

CSRF : Cross-site request forgery is a web security vulnerability that allows an attacker to induce users to perform actions that they do not intend to perform.

Affected Versions:
Waitlist Woocommerce plugins before version 2.5.2

Successful exploitation of this vulnerability may allow remote attackers to update arbitrary options on a site that can be used to create an administrative user account and grant full privileged access to a compromised site.

  • CVSS V3 rated as Critical - 8.8 severity.
  • CVSS V2 rated as High - 6.8 severity.
  • Solution
    Customers are advised to upgrade to a fixed version Waitlist For Woocommerce 2.5.2 or later versions to remediate this vulnerability.
    Please refer to Wordfence security blog.

    CVEs related to QID 150458

    Software Advisories
    Advisory ID Software Component Link
    Wordfence URL Logo www.wordfence.com/blog/2022/01/84000-wordpress-sites-affected-by-three-plugins-with-the-same-vulnerability/