Back

MEDIUM

Product Slider for WooCommerce < 2.5.7 - Subscriber+ Arbitrary Options Deletion

Published Aug 22, 2022

Description

The Product Slider for WooCommerce WordPress plugin before 2.5.7 has flawed CSRF checks and lack authorisation in some of its AJAX actions, allowing any authenticated users, such as subscriber to call them. One in particular could allow them to delete arbitrary blog options.

Affected products

Remediation

No remediation recorded yet.

References (2)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner WPScan
Published Aug 22, 2022
Updated Aug 3, 2024
Reserved Jul 11, 2022

CISA Vulnrichment

No data

NVD

Status Modified
Modified Jun 17, 2026

Red Hat

No data

ENISA EUVD

Assigner WPScan
Published Aug 22, 2022
Updated Aug 3, 2024

GitHub

No data