CVE-2022-46796: WordPress CURCY plugin <= 2.1.25 - Unauthenticated plugin settings change vulnerability
Missing Authorization vulnerability in VillaTheme CURCY woo-multi-currency allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects CURCY: from n/a through <= 2.1.25.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2022-46796?
The severity of CVE-2022-46796 has not been officially assigned, but it involves a significant risk due to missing authorization leading to potential unauthorized access.
How do I fix CVE-2022-46796?
To fix CVE-2022-46796, update the VillaTheme CURCY plugin to version 2.1.26 or higher where the vulnerability is addressed.
Which versions of CURCY are affected by CVE-2022-46796?
CVE-2022-46796 affects VillaTheme CURCY versions up to and including 2.1.25.
What type of vulnerability is CVE-2022-46796?
CVE-2022-46796 is classified as a Missing Authorization vulnerability related to incorrectly configured access controls.
Who is affected by CVE-2022-46796?
Users of VillaTheme CURCY and WordPress CURCY Plugin versions up to 2.1.25 may be impacted by CVE-2022-46796.