CVE-2022-40198: WordPress TeraWallet – For WooCommerce Plugin <= 1.3.24 is vulnerable to Cross Site Request Forgery (CSRF)
Published Mar 1, 2023
·Updated
Cross-Site Request Forgery (CSRF) vulnerability in StandaloneTech TeraWallet – For WooCommerce plugin <= 1.3.24 leading to plugin settings change.
Affected Software
1 affected component
StandaloneTech Terawallet Wordpress<1.4.0
Remediation
Information
Update to 1.4.0 or a higher version.
Event History
Mar 1, 2023
CVE Published
via MITRE·01:11 PM
Data Sourced
via MITRE·01:11 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID of this CSRF vulnerability?
The vulnerability ID for this CSRF vulnerability is CVE-2022-40198.
2
What is the affected software?
The affected software is StandaloneTech TeraWallet plugin for WooCommerce version <= 1.3.24.
3
What is the severity of this vulnerability?
The severity of this vulnerability is medium with a CVSS score of 4.3.
4
What is the CWE associated with this vulnerability?
The CWE associated with this vulnerability is CWE-352.
5
How can I fix this CSRF vulnerability in StandaloneTech TeraWallet?
To fix this CSRF vulnerability, you need to update the StandaloneTech TeraWallet plugin to version 1.4.0 or newer.