The Role Based Pricing for WooCommerce WordPress plugin before 1.6.3 does not have authorisation and proper CSRF checks, as well as does not validate path given via user input, allowing any authenticated users like subscriber to perform PHAR deserialization attacks when they can upload a file, and a suitable gadget chain is present on the blog
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: WPScan
Published: 2022-11-07T00:00:00
Updated: 2024-08-03T01:14:02.420Z
Reserved: 2022-10-17T00:00:00
Link: CVE-2022-3536
Vulnrichment
No data.
NVD
Status : Modified
Published: 2022-11-07T10:15:12.093
Modified: 2024-11-21T07:19:43.240
Link: CVE-2022-3536
Redhat
No data.