CVE-2022-3451: Product Stock Manager < 1.0.5 - Subscriber+ Unauthorised AJAX Calls
The Product Stock Manager WordPress plugin before 1.0.5 does not have authorisation and proper CSRF checks in multiple AJAX actions, allowing users with a role as low as subscriber to call them. One action in particular could allow to update arbitrary options
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-3451?
CVE-2022-3451 is a vulnerability in the Product Stock Manager WordPress plugin that allows users with low roles to call multiple AJAX actions without authorization and proper CSRF checks.
How severe is CVE-2022-3451?
CVE-2022-3451 has a severity level of medium, with a severity value of 4.3.
What is affected by CVE-2022-3451?
The Addify Product Stock Manager WordPress plugin versions up to and excluding 1.0.5 are affected by CVE-2022-3451.
What can an attacker do with CVE-2022-3451?
With CVE-2022-3451, an attacker with a role as low as a subscriber can call multiple AJAX actions, potentially leading to unauthorized updates of arbitrary options.
How can I mitigate CVE-2022-3451?
To mitigate CVE-2022-3451, it is recommended to update the Addify Product Stock Manager WordPress plugin to version 1.0.5 or newer.