CVE-2022-2389: Automations By Autonami < 2.1.2 - Subscriber+ Automation Creation
The Abandoned Cart Recovery for WooCommerce, Follow Up Emails, Newsletter Builder & Marketing Automation By Autonami WordPress plugin before 2.1.2 does not have authorisation and CSRF checks in one of its AJAX action, allowing any authenticated users, such as subscriber to create automations
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-2389?
CVE-2022-2389 has a medium severity rating due to the lack of authorization and CSRF checks in the affected WordPress plugin.
How do I fix CVE-2022-2389?
To fix CVE-2022-2389, update the Abandoned Cart Recovery for WooCommerce plugin to version 2.1.2 or later.
What versions are affected by CVE-2022-2389?
CVE-2022-2389 affects versions of the Abandoned Cart Recovery for WooCommerce plugin prior to 2.1.2.
Who is impacted by CVE-2022-2389?
Authenticated users, including those with subscriber roles, are impacted by CVE-2022-2389 as they can exploit the vulnerability.
What type of attacks can CVE-2022-2389 allow?
CVE-2022-2389 can allow unauthorized authenticated users to create automated campaign actions.