CVE-2022-45371: WordPress ShopEngine Plugin <= 4.1.1 is vulnerable to Cross Site Request Forgery (CSRF)
Cross-Site Request Forgery (CSRF) vulnerability in Wpmet ShopEngine plugin <= 4.1.1 versions.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2022-45371?
CVE-2022-45371 is a Cross-Site Request Forgery (CSRF) vulnerability in the Wpmet ShopEngine plugin version 4.1.1 and below.
What is the severity of CVE-2022-45371?
The severity of CVE-2022-45371 is high, with a CVSS score of 8.8.
How does the CSRF vulnerability in Wpmet ShopEngine plugin work?
The CSRF vulnerability in Wpmet ShopEngine plugin allows an attacker to perform unauthorized actions on behalf of authenticated users.
Is there a fix available for CVE-2022-45371?
Yes, a fix for CVE-2022-45371 is available. It is recommended to update to Wpmet ShopEngine plugin version 4.1.2 or later.
Where can I find more information about CVE-2022-45371?
More information about CVE-2022-45371 can be found at the Patchstack database: https://patchstack.com/database/vulnerability/shopengine/wordpress-shopengine-plugin-4-1-1-cross-site-request-forgery-csrf-vulnerability?_s_id=cve