Multivendor Marketplace Solution for WooCommerce < 3.8.12 - Unauthorised AJAX Calls
Vulnerability Description
The Multivendor Marketplace Solution for WooCommerce WordPress plugin before 3.8.12 is lacking authorisation and CSRF in multiple AJAX actions, which could allow any authenticated users, such as subscriber to call them and suspend vendors (reporter by the submitter) or update arbitrary order status (identified by WPScan when verifying the issue) for example. Other unauthenticated attacks are also possible, either directly or via CSRF
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2022-2657
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- ptsfence
More from Unknown
View All →Affected Vendor
Unknown
View all reports →