CVE-2022-38134: WordPress Customer Reviews for WooCommerce plugin <= 5.3.5 - Authenticated Broken Access Control vulnerability
Authenticated (subscriber+) Broken Access Control vulnerability in Customer Reviews for WooCommerce plugin <= 5.3.5 at WordPress.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2022-38134?
CVE-2022-38134 is classified as a medium severity vulnerability due to its potential for authenticated access abuse.
How do I fix CVE-2022-38134?
To fix CVE-2022-38134, update the Customer Reviews for WooCommerce plugin to the latest version that exceeds 5.3.5.
Who is affected by CVE-2022-38134?
Any authenticated user with subscriber or higher roles using Customer Reviews for WooCommerce plugin versions 5.3.5 or lower is affected by CVE-2022-38134.
What type of vulnerability is CVE-2022-38134?
CVE-2022-38134 is categorized as a Broken Access Control vulnerability that affects the Customer Reviews for WooCommerce plugin.
What can attackers do with CVE-2022-38134?
Attackers exploiting CVE-2022-38134 can gain unauthorized access to sensitive functionalities within the Customer Reviews for WooCommerce plugin.