CVE-2022-0775

MEDIUM

WooCommerce <6.2.1 - Privilege Escalation

Title source: llm
STIX 2.1

Description

The WooCommerce WordPress plugin before 6.2.1 does not have proper authorisation check when deleting reviews, which could allow any authenticated users, such as subscriber to delete arbitrary comment

References (3)

Core 3

Scores

CVSS v3 4.3
EPSS 0.0067
EPSS Percentile 47.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-863
Status published
Products (1)
woocommerce/woocommerce < 6.2.1
Published Jan 16, 2024
Tracked Since Feb 18, 2026