CVE-2022-3923: ActiveCampaign for WooCommerce < 1.9.8 - Subscriber+ Error Log Cleanup
The ActiveCampaign for WooCommerce WordPress plugin before 1.9.8 does not have authorisation check when cleaning up its error logs via an AJAX action, which could allow any authenticated users, such as subscriber to call it and remove error logs.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-3923?
The severity of CVE-2022-3923 is medium with a severity value of 4.3.
How does CVE-2022-3923 affect ActiveCampaign for WooCommerce WordPress plugin?
CVE-2022-3923 affects ActiveCampaign for WooCommerce WordPress plugin versions before 1.9.8.
What can an attacker do with CVE-2022-3923?
An authenticated attacker can use CVE-2022-3923 to remove error logs from ActiveCampaign for WooCommerce WordPress plugin.
How can I fix CVE-2022-3923?
To fix CVE-2022-3923, update ActiveCampaign for WooCommerce WordPress plugin to version 1.9.8 or later.
Are there any references for CVE-2022-3923?
Yes, you can find more information about CVE-2022-3923 at https://wpscan.com/vulnerability/6536946a-7ebf-4f8f-9446-36ec2a2a3ad2.