CVE-2022-36401: WordPress TeraWallet – For WooCommerce Plugin <= 1.3.24 is vulnerable to Cross Site Request Forgery (CSRF)
Published Feb 2, 2023
·Updated
Cross-Site Request Forgery (CSRF) vulnerability in TeraWallet – For WooCommerce plugin <= 1.3.24 versions.
Affected Software
1 affected component
StandaloneTech Terawallet Wordpress<1.4.0
Remediation
Information
Update to 1.4.0 or higher version.
Event History
Feb 2, 2023
CVE Published
via MITRE·03:45 PM
Data Sourced
via MITRE·03:45 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2022-36401?
CVE-2022-36401 is classified as a medium severity Cross-Site Request Forgery (CSRF) vulnerability.
2
How do I fix CVE-2022-36401?
To fix CVE-2022-36401, you should update the TeraWallet – For WooCommerce plugin to version 1.4.0 or higher.
3
Who is affected by CVE-2022-36401?
Any user running TeraWallet – For WooCommerce plugin version 1.3.24 or earlier is affected by CVE-2022-36401.
4
What type of vulnerability is CVE-2022-36401?
CVE-2022-36401 is a Cross-Site Request Forgery (CSRF) vulnerability.
5
What impact does CVE-2022-36401 have?
CVE-2022-36401 could allow an attacker to perform unauthorized actions on behalf of the user without their consent.