CVE-2022-2382: Product Slider for WooCommerce < 2.5.7 - Subscriber+ Arbitrary Options Deletion
The Product Slider for WooCommerce WordPress plugin before 2.5.7 has flawed CSRF checks and lack authorisation in some of its AJAX actions, allowing any authenticated users, such as subscriber to call them. One in particular could allow them to delete arbitrary blog options.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-2382?
CVE-2022-2382 is a vulnerability in the Product Slider for WooCommerce WordPress plugin before version 2.5.7.
What is the severity of CVE-2022-2382?
CVE-2022-2382 has a severity score of 4.3, which is considered medium.
What is the affected software for CVE-2022-2382?
The affected software for CVE-2022-2382 is the Product Slider for WooCommerce WordPress plugin before version 2.5.7.
What is the impact of CVE-2022-2382?
CVE-2022-2382 allows authenticated users, such as subscribers, to call certain AJAX actions and delete arbitrary blog options.
How can I fix CVE-2022-2382?
To fix CVE-2022-2382, update the Product Slider for WooCommerce WordPress plugin to version 2.5.7 or newer.