CVE-2022-4363: Wholesale Market <= 2.2.2 - Settings Update via CSRF
The Wholesale Market WordPress plugin before 2.2.2, Wholesale Market for WooCommerce WordPress plugin before 2.0.1 have a flawed CSRF check when updating their settings, which could allow attackers to make a logged in admin update them via a CSRF attack
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-4363?
CVE-2022-4363 has a medium severity rating due to the potential for attackers to exploit the flawed CSRF check.
How do I fix CVE-2022-4363?
To fix CVE-2022-4363, update the Wholesale Market plugin to version 2.2.2 or the Wholesale Market for WooCommerce plugin to version 2.0.1 or later.
What causes CVE-2022-4363?
CVE-2022-4363 is caused by a flawed CSRF check when updating settings in the affected plugins.
Who is affected by CVE-2022-4363?
Users of the Wholesale Market plugin prior to version 2.2.2 and the Wholesale Market for WooCommerce plugin prior to version 2.0.1 are affected by CVE-2022-4363.
Can CVE-2022-4363 lead to unauthorized access?
Yes, CVE-2022-4363 can allow attackers to perform unauthorized updates to settings by exploiting the CSRF vulnerability.