The Role Based Pricing for WooCommerce WordPress plugin before 1.6.3 does not have authorisation and proper CSRF checks, as well as does not validate path given via user input, allowing any authenticated users like subscriber to perform PHAR deserialization attacks when they can upload a file, and a suitable gadget chain is present on the blog
Metrics
Affected Vendors & Products
References
History
Thu, 01 May 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: WPScan
Published: 2022-11-07T00:00:00.000Z
Updated: 2025-05-01T19:26:42.686Z
Reserved: 2022-10-17T00:00:00.000Z
Link: CVE-2022-3536
Updated: 2024-08-03T01:14:02.420Z
Status : Modified
Published: 2022-11-07T10:15:12.093
Modified: 2025-05-01T20:15:33.907
Link: CVE-2022-3536
No data.
ReportizFlow