CVE-2022-46798: WordPress WooLentor Plugin <= 2.5.1 is vulnerable to Cross Site Request Forgery (CSRF)
Published Mar 1, 2023
·Updated
Cross-Site Request Forgery (CSRF) vulnerability in HasThemes ShopLentor plugin <= 2.5.1 leading to plugin settings change.
Affected Software
1 affected component
HasThemes Woolentor - Woocommerce Elementor Addons \+ Builder Wordpress<2.5.2
Remediation
Information
Update to 2.5.2 or a higher version.
Event History
Mar 1, 2023
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the CVE ID of this vulnerability?
The CVE ID of this vulnerability is CVE-2022-46798.
2
What is the title of this vulnerability?
The title of this vulnerability is 'Cross-Site Request Forgery (CSRF) vulnerability in HasThemes ShopLentor plugin <= 2.5.1 leading to plugin settings change.'
3
What is the affected software?
The affected software is HasThemes ShopLentor plugin <= 2.5.1.
4
What is the severity of CVE-2022-46798?
The severity of CVE-2022-46798 is medium with a CVSS score of 5.4.
5
How can I fix this vulnerability?
To fix this vulnerability, update the HasThemes ShopLentor plugin to version 2.5.2 or later.