CVE-2022-3459
Last modified
CVE-2022-3459 is a medium-severity vulnerability rated 5.3/10 on the CVSS scale. The WooCommerce Multiple Free Gift plugin for WordPress is vulnerable to gift manipulation in all versions up to, and including, 1.2.3. This is due to plugin not enforcing server-side checks on the products that can be added as a gift. EPSS estimates a 0.32% chance of exploitation in the next 30 days.
Description
The WooCommerce Multiple Free Gift plugin for WordPress is vulnerable to gift manipulation in all versions up to, and including, 1.2.3. This is due to plugin not enforcing server-side checks on the products that can be added as a gift. This makes it possible for unauthenticated attackers to add non-gift items to their cart as a gift.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Lilmonkee | Woocommerce Multiple Free Gift | <= 1.2.3 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2022-3459?
How severe is CVE-2022-3459?
How do I fix CVE-2022-3459?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2022
- CVE-2022-34577A vulnerability in adm.cgi of WAVLINK WN535 G3 M35G3R.V5030.…9.8
- CVE-2022-34578Open Source Point of Sale v3.3.7 was discovered to contain a…7.2
- CVE-2022-3458A vulnerability has been found in SourceCodester Human Resou…9.8
- CVE-2022-34580Advanced School Management System v1.0 was discovered to con…4.8
- CVE-2022-34586itsourcecode Advanced School Management System v1.0 is vulne…8.8
- CVE-2022-34588itsourcecode Advanced School Management System v1.0 is vulne…8.8
- CVE-2022-34590Hospital Management System v1.0 was discovered to contain a …7.2
- CVE-2022-34592Wavlink WL-WN575A3 RPT75A3.V4300.201217 was discovered to co…9.8
- CVE-2022-34593DPTech VPN v8.1.28.0 was discovered to contain an arbitrary …7.5
- CVE-2022-34594Advanced School Management System v1.0 was discovered to con…4.8
- CVE-2022-34595Tenda AX1803 v1.0.0.1_2890 was discovered to contain a comma…9.8
- CVE-2022-34596Tenda AX1803 v1.0.0.1_2890 was discovered to contain a comma…9.8
Are you affected by CVE-2022-3459?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
