Security Advisory

CVE-2022-4426

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2023-01-09 22:13:41
Last updated 2025-04-09 18:39:34
Assigner WPScan
State PUBLISHED

Description

The Mautic Integration for WooCommerce WordPress plugin before 1.0.3 does not have proper CSRF check when updating settings, and does not ensure that the options to be updated belong to the plugin, allowing attackers to make a logged in admin change arbitrary blog options via a CSRF attack.