CVE-2022-46806: WordPress Cart All In One For WooCommerce Plugin <= 1.1.10 is vulnerable to Cross Site Request Forgery (CSRF)
Published Mar 1, 2023
·Updated
Cross-Site Request Forgery (CSRF) vulnerability in VillaTheme Cart All In One For WooCommerce plugin <= 1.1.10 leading to cart modification.
Affected Software
1 affected component
Villatheme Cart All In One For Woocommerce Wordpress<1.1.11
Remediation
Information
Update to 1.1.11 or a higher version.
Event History
Mar 1, 2023
CVE Published
via MITRE·02:16 PM
Data Sourced
via MITRE·02:16 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2022-46806?
CVE-2022-46806 is a Cross-Site Request Forgery (CSRF) vulnerability in the VillaTheme Cart All In One For WooCommerce plugin <= 1.1.10 leading to cart modification.
2
What is the severity of CVE-2022-46806?
CVE-2022-46806 has a severity rating of medium (4.3).
3
How does CVE-2022-46806 affect Villatheme Cart All In One For Woocommerce?
CVE-2022-46806 affects Villatheme Cart All In One For Woocommerce plugin version <= 1.1.10, allowing for potential cart modification via Cross-Site Request Forgery.
4
Is there a patch available for CVE-2022-46806?
Yes, a patch is available. Please refer to the official reference for more details.
5
What is the Common Weakness Enumeration (CWE) identifier for CVE-2022-46806?
The Common Weakness Enumeration (CWE) identifier for CVE-2022-46806 is CWE-352.