CVE-2022-4426
Last modified
CVE-2022-4426 is a medium-severity vulnerability rated 4.3/10 on the CVSS scale. The Mautic Integration for WooCommerce WordPress plugin before 1.0.3 does not have proper CSRF check when updating settings, and does not ensure that the options to be updated belong to the plugin, allowing attackers to make a logged in admin change arbitrary blog options via a CSRF attack.. EPSS estimates a 0.31% chance of exploitation in the next 30 days.
Description
The Mautic Integration for WooCommerce WordPress plugin before 1.0.3 does not have proper CSRF check when updating settings, and does not ensure that the options to be updated belong to the plugin, allowing attackers to make a logged in admin change arbitrary blog options via a CSRF attack.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Wpswings | Mautic Integration For Woocommerce | < 1.0.3 |
References
- https://wpscan.com/vulnerability/7d3d6b9c-d1c1-4e23-b891-7c72e4e89c38Exploit, Third Party Advisory
- https://wpscan.com/vulnerability/7d3d6b9c-d1c1-4e23-b891-7c72e4e89c38Exploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-4426?
How severe is CVE-2022-4426?
How do I fix CVE-2022-4426?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2022
- CVE-2022-44254TOTOLINK LR350 V9.3.5u.6369_B20220309 contains a post-authen…8.8
- CVE-2022-44255TOTOLINK LR350 V9.3.5u.6369_B20220309 contains a pre-authent…9.8
- CVE-2022-44256TOTOLINK LR350 V9.3.5u.6369_B20220309 contains a post-authen…8.8
- CVE-2022-44257TOTOLINK LR350 V9.3.5u.6369_B20220309 contains a post-authen…8.8
- CVE-2022-44258TOTOLINK LR350 V9.3.5u.6369_B20220309 contains a post-authen…8.8
- CVE-2022-44259TOTOLINK LR350 V9.3.5u.6369_B20220309 contains a post-authen…8.8
- CVE-2022-44260TOTOLINK LR350 V9.3.5u.6369_B20220309 contains a post-authen…8.8
- CVE-2022-44261Avery Dennison Monarch Printer M9855 is vulnerable to Cross …6.1
- CVE-2022-44262ff4j 1.8.1 is vulnerable to Remote Code Execution (RCE).9.8
- CVE-2022-44263Dentsply Sirona Sidexis <= 4.3 is vulnerable to Incorrect Ac…7.8
- CVE-2022-44264Dentsply Sirona Sidexis <= 4.3 is vulnerable to Unquoted Ser…7.8
- CVE-2022-44267ImageMagick 7.1.0-49 is vulnerable to Denial of Service. Whe…6.5
Are you affected by CVE-2022-4426?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
