CVE-2022-3536: Role Based Pricing for WooCommerce < 1.6.3 - Subscriber+ PHAR Deserialization
The Role Based Pricing for WooCommerce WordPress plugin before 1.6.3 does not have authorisation and proper CSRF checks, as well as does not validate path given via user input, allowing any authenticated users like subscriber to perform PHAR deserialization attacks when they can upload a file, and a suitable gadget chain is present on the blog
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-3536?
CVE-2022-3536 is a vulnerability in the Role Based Pricing for WooCommerce WordPress plugin before version 1.6.3.
What is the severity of CVE-2022-3536?
CVE-2022-3536 has a severity rating of 8.8 (high).
How does CVE-2022-3536 affect the Role Based Pricing for WooCommerce WordPress plugin?
CVE-2022-3536 affects the Role Based Pricing for WooCommerce WordPress plugin before version 1.6.3.
What is the risk of CVE-2022-3536?
CVE-2022-3536 poses a high risk as it allows authenticated users to perform PHAR deserialization attacks.
Is there a fix available for CVE-2022-3536?
Yes, the fix for CVE-2022-3536 is to update the Role Based Pricing for WooCommerce WordPress plugin to version 1.6.3 or later.