CVE-2022-38134

Authenticated (subscriber+) Broken Access Control vulnerability in Customer Reviews for WooCommerce plugin <= 5.3.5 at WordPress.
Configurations

Configuration 1 (hide)

cpe:2.3:a:cusrev:customer_reviews_for_woocommerce:*:*:*:*:*:wordpress:*:*

History

27 Jun 2023, 20:00

Type Values Removed Values Added
CWE CWE-264 NVD-CWE-Other

26 Sep 2022, 15:26

Type Values Removed Values Added
References (CONFIRM) https://wordpress.org/plugins/customer-reviews-woocommerce/#developers - (CONFIRM) https://wordpress.org/plugins/customer-reviews-woocommerce/#developers - Product
References (CONFIRM) https://patchstack.com/database/vulnerability/customer-reviews-woocommerce/wordpress-customer-reviews-for-woocommerce-plugin-5-3-5-authenticated-broken-access-control-vulnerability/_s_id=cve - (CONFIRM) https://patchstack.com/database/vulnerability/customer-reviews-woocommerce/wordpress-customer-reviews-for-woocommerce-plugin-5-3-5-authenticated-broken-access-control-vulnerability/_s_id=cve - Broken Link
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.8
CPE cpe:2.3:a:cusrev:customer_reviews_for_woocommerce:*:*:*:*:*:wordpress:*:*
First Time Cusrev
Cusrev customer Reviews For Woocommerce

23 Sep 2022, 16:31

Type Values Removed Values Added
New CVE

Information

Published : 2022-09-23 16:15

Updated : 2023-12-10 14:35


NVD link : CVE-2022-38134

Mitre link : CVE-2022-38134

CVE.ORG link : CVE-2022-38134


JSON object : View

Products Affected

cusrev

  • customer_reviews_for_woocommerce
CWE
NVD-CWE-Other CWE-264

Permissions, Privileges, and Access Controls