CVE-2022-44630: WordPress YITH WooCommerce Product Slider Carousel plugin <= 1.16.0 - Cross-Site Request Forgery (CSRF)
Cross-Site request forgery (CSRF) vulnerability in YITH YITH WooCommerce Product Slider Carousel allows Cross Site Request Forgery.
This issue affects YITH WooCommerce Product Slider Carousel: from n/a through 1.16.0.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
wordpress/yith-woocommerce-product-slider-carouselto a version that resolves this vulnerability.Fixed in 1.16.1
Event History
Frequently Asked Questions
What is the severity of CVE-2022-44630?
CVE-2022-44630 has a medium severity rating of 4.6.
How do I fix CVE-2022-44630?
To fix CVE-2022-44630, update the YITH WooCommerce Product Slider Carousel plugin to version 1.16.1 or later.
What type of vulnerability is CVE-2022-44630?
CVE-2022-44630 is a Cross-Site Request Forgery (CSRF) vulnerability.
Which software is affected by CVE-2022-44630?
CVE-2022-44630 affects the YITH WooCommerce Product Slider Carousel plugin versions up to 1.16.0.
What are the risks associated with CVE-2022-44630?
The risks associated with CVE-2022-44630 include potential unauthorized actions being performed on behalf of users.