Beveiligingsadvies

CVE-2022-36284

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2022-08-05 15:08:51
Laatst bijgewerkt 2026-04-28 16:07:44
Toegewezen door Patchstack
CVSS-score 6.4
Status PUBLISHED

Beschrijving

Authenticated IDOR vulnerability in StoreApps Affiliate For WooCommerce premium plugin <= 4.7.0 at WordPress allows an attacker to change the PayPal email. WooCommerce PayPal Payments plugin (free) should be at least installed to get the extra input field on the user profile page.