Логотип exploitDog
bind:CVE-2022-3459
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2022-3459

Количество 2

Количество 2

nvd логотип

CVE-2022-3459

больше 1 года назад

The WooCommerce Multiple Free Gift plugin for WordPress is vulnerable to gift manipulation in all versions up to, and including, 1.2.3. This is due to plugin not enforcing server-side checks on the products that can be added as a gift. This makes it possible for unauthenticated attackers to add non-gift items to their cart as a gift.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-rpwv-q4ch-7pvm

больше 1 года назад

The WooCommerce Multiple Free Gift plugin for WordPress is vulnerable to gift manipulation in all versions up to, and including, 1.2.3. This is due to plugin not enforcing server-side checks on the products that can be added as a gift. This makes it possible for unauthenticated attackers to add non-gift items to their cart as a gift.

CVSS3: 5.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2022-3459

The WooCommerce Multiple Free Gift plugin for WordPress is vulnerable to gift manipulation in all versions up to, and including, 1.2.3. This is due to plugin not enforcing server-side checks on the products that can be added as a gift. This makes it possible for unauthenticated attackers to add non-gift items to their cart as a gift.

CVSS3: 5.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-rpwv-q4ch-7pvm

The WooCommerce Multiple Free Gift plugin for WordPress is vulnerable to gift manipulation in all versions up to, and including, 1.2.3. This is due to plugin not enforcing server-side checks on the products that can be added as a gift. This makes it possible for unauthenticated attackers to add non-gift items to their cart as a gift.

CVSS3: 5.3
0%
Низкий
больше 1 года назад

Уязвимостей на страницу