CVE-2022-47150: WordPress WooCommerce Conversion Tracking plugin <= 2.0.10 - Cross-Site Request Forgery (CSRF) vulnerability
Cross-Site request forgery (CSRF) vulnerability in weDevs WooCommerce Conversion Tracking allows Cross Site Request Forgery.
This issue affects WooCommerce Conversion Tracking: from n/a through 2.0.10.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress WooCommerce Conversion Tracking pluginto a version that resolves this vulnerability.Fixed in 2.0.11
Event History
Frequently Asked Questions
What is the severity of CVE-2022-47150?
The severity of CVE-2022-47150 is classified as medium with a score of 4.3.
How does CVE-2022-47150 affect my WordPress site?
CVE-2022-47150 allows for Cross-Site Request Forgery (CSRF), potentially enabling attackers to perform actions on behalf of victims.
How do I fix CVE-2022-47150?
To fix CVE-2022-47150, update the WooCommerce Conversion Tracking plugin to at least version 2.0.11.
Which versions of the WooCommerce Conversion Tracking plugin are affected by CVE-2022-47150?
CVE-2022-47150 affects WooCommerce Conversion Tracking plugin versions from n/a through 2.0.10.
What type of vulnerability is CVE-2022-47150 classified as?
CVE-2022-47150 is classified as a Cross-Site Request Forgery (CSRF) vulnerability.