Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-15868 | The WooCommerce Affiliate Plugin WordPress plugin before 4.16.4.5 does not have authorization and CSRF checks on a specific action handler, as well as does not sanitize its settings, which enables an unauthenticated attacker to inject malicious XSS payloads into the settings page of the plugin. |
No history.
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2024-08-02T23:40:04.463Z
Reserved: 2022-03-01T00:00:00.000Z
Link: CVE-2022-0818
No data.
Status : Modified
Published: 2022-03-28T18:15:09.843
Modified: 2026-06-17T04:21:18.617
Link: CVE-2022-0818
No data.
OpenCVE Enrichment
No data.
-
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
EUVD