CVE-2022-46811: WordPress ALD Dropshipping and Fulfillment for AliExpress and WooCommerce plugin <= 1.0.21 - Broken Access Control + CSRF
Missing Authorization vulnerability in VillaTheme ALD – Dropshipping and Fulfillment for AliExpress and WooCommerce woo-alidropship allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ALD – Dropshipping and Fulfillment for AliExpress and WooCommerce: from n/a through <= 1.0.21.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2022-46811?
CVE-2022-46811 is classified as a missing authorization vulnerability that allows exploitation of incorrectly configured access control security levels.
How do I fix CVE-2022-46811?
To remediate CVE-2022-46811, update the ALD – Dropshipping and Fulfillment for AliExpress and WooCommerce plugin to version 1.0.22 or later.
What software is affected by CVE-2022-46811?
CVE-2022-46811 affects versions up to and including 1.0.21 of the ALD – Dropshipping and Fulfillment for AliExpress and WooCommerce plugin.
What type of vulnerability is CVE-2022-46811?
CVE-2022-46811 is categorized as a missing authorization vulnerability involving broken access control.
Can CVE-2022-46811 be exploited remotely?
Yes, CVE-2022-46811 can potentially be exploited remotely due to the nature of the access control misconfiguration.