CVE-2022-0775: WooCommerce < 6.2.1 - Subscriber+ Arbitrary Comment Deletion
Published Jan 16, 2024
·Updated
The WooCommerce WordPress plugin before 6.2.1 does not have proper authorisation check when deleting reviews, which could allow any authenticated users, such as subscriber to delete arbitrary comment
Affected Software
1 affected component
WooCommerce WooCommerce WordPress<6.2.1
Remediation
Patch Available
Event History
Jan 16, 2024
CVE Published
via MITRE·03:52 PM
Data Sourced
via MITRE·03:52 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2022-0775?
CVE-2022-0775 has a medium severity rating as it impacts authorization checks for deleting reviews.
2
How do I fix CVE-2022-0775?
To fix CVE-2022-0775, update the WooCommerce plugin to version 6.2.1 or later.
3
Who is affected by CVE-2022-0775?
Any user with authenticated access, including subscribers, is affected by CVE-2022-0775.
4
What type of vulnerability is CVE-2022-0775?
CVE-2022-0775 is an authorization vulnerability in the WooCommerce WordPress plugin.
5
When was CVE-2022-0775 disclosed?
CVE-2022-0775 was disclosed in February 2022.