First published: Tue Jan 16 2024(Updated: )
The WPGraphQL WooCommerce WordPress plugin before 0.12.4 does not prevent unauthenticated attackers from enumerating a shop's coupon codes and values via GraphQL.
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
WPEngine WPGraphQL | <=0.12.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-1563 is classified as a medium severity vulnerability due to its ability to allow unauthorized coupon code enumeration.
To fix CVE-2022-1563, update the WPGraphQL WooCommerce WordPress plugin to version 0.12.4 or later.
CVE-2022-1563 affects users of the WPGraphQL WooCommerce WordPress plugin versions prior to 0.12.4.
The risks associated with CVE-2022-1563 include unauthorized attackers being able to view and enumerate coupon codes and their values.
Yes, CVE-2022-1563 can be exploited remotely by unauthenticated attackers through GraphQL queries.