CVE-2022-4426: Mautic Integration For WooCommerce < 1.0.3 - Arbitrary Options Update via CSRF
The Mautic Integration for WooCommerce WordPress plugin before 1.0.3 does not have proper CSRF check when updating settings, and does not ensure that the options to be updated belong to the plugin, allowing attackers to make a logged in admin change arbitrary blog options via a CSRF attack.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-4426?
CVE-2022-4426 has been classified with a medium severity level due to its potential impact on WordPress website security.
How do I fix CVE-2022-4426?
To fix CVE-2022-4426, update the Mautic Integration for WooCommerce WordPress plugin to version 1.0.3 or higher.
What are the consequences of CVE-2022-4426 exploitation?
Exploitation of CVE-2022-4426 can allow attackers to change arbitrary blog options, compromising site integrity.
Who is affected by CVE-2022-4426?
Users of the Mautic Integration for WooCommerce plugin prior to version 1.0.3 on WordPress installations are affected by CVE-2022-4426.
What type of vulnerability is CVE-2022-4426?
CVE-2022-4426 is categorized as a Cross-Site Request Forgery (CSRF) vulnerability.