Description
The Product Stock Manager WordPress plugin before 1.0.5 does not have authorisation and proper CSRF checks in multiple AJAX actions, allowing users with a role as low as subscriber to call them. One action in particular could allow to update arbitrary options
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-42825 | The Product Stock Manager WordPress plugin before 1.0.5 does not have authorisation and proper CSRF checks in multiple AJAX actions, allowing users with a role as low as subscriber to call them. One action in particular could allow to update arbitrary options |
References
History
Thu, 01 May 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2025-05-01T20:43:37.425Z
Reserved: 2022-10-11T00:00:00.000Z
Link: CVE-2022-3451
Updated: 2024-08-03T01:07:06.695Z
Status : Modified
Published: 2022-11-07T10:15:11.710
Modified: 2025-05-01T21:15:51.120
Link: CVE-2022-3451
No data.
OpenCVE Enrichment
No data.
EUVD