CVE-2022-38470: WordPress Customer Reviews for WooCommerce plugin <= 5.3.5 - Cross-Site Request Forgery (CSRF) vulnerability
Published Sep 23, 2022
·Updated
Cross-Site Request Forgery (CSRF) vulnerability in Customer Reviews for WooCommerce plugin <= 5.3.5 at WordPress.
Affected Software
1 affected component
CusRev Customer Reviews For Woocommerce Wordpress<=5.3.5
Remediation
Information
Update to 5.3.6 or higher version.
Event History
Sep 23, 2022
CVE Published
via MITRE·03:08 PM
Data Sourced
via MITRE·03:08 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2022-38470?
CVE-2022-38470 is classified as a medium severity Cross-Site Request Forgery (CSRF) vulnerability.
2
How do I fix CVE-2022-38470?
To fix CVE-2022-38470, update the Customer Reviews for WooCommerce plugin to version 5.3.6 or later.
3
What versions are affected by CVE-2022-38470?
CVE-2022-38470 affects Customer Reviews for WooCommerce plugin versions up to and including 5.3.5.
4
What type of vulnerability is CVE-2022-38470?
CVE-2022-38470 is a Cross-Site Request Forgery (CSRF) vulnerability.
5
What can an attacker do with CVE-2022-38470?
An attacker can exploit CVE-2022-38470 to perform unauthorized actions on behalf of a user without their consent.