CVE-2022-0707: Easy Digital Downloads < 2.11.6 - Arbitrary Payment Note Insertion via CSRF
The Easy Digital Downloads WordPress plugin before 2.11.6 does not have CSRF check in place when inserting payment notes, which could allow attackers to make a logged admin insert arbitrary notes via a CSRF attack
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID of this issue?
The vulnerability ID of this issue is CVE-2022-0707.
What is the severity of CVE-2022-0707?
The severity of CVE-2022-0707 is medium with a CVSS score of 4.3.
What is the affected software?
The affected software is the Easy Digital Downloads WordPress plugin up to and including version 2.11.6.
What is the impact of this vulnerability?
This vulnerability allows attackers to make a logged admin insert arbitrary notes via a CSRF attack.
Are there any references for this vulnerability?
Yes, you can find references for this vulnerability at the following links: [Reference 1](https://plugins.trac.wordpress.org/changeset/2697388), [Reference 2](https://wpscan.com/vulnerability/50680797-61e4-4737-898f-e5b394d89117).