Record summary

CVE-2022-0818 has a selected CVSS score of 6.1 (medium); EIP currently links 2 curated repository PoCs.

Description

The WooCommerce Affiliate Plugin WordPress plugin before 4.16.4.5 does not have authorization and CSRF checks on a specific action handler, as well as does not sanitize its settings, which enables an unauthenticated attacker to inject malicious XSS payloads into the settings page of the plugin.

Description source: CVE List

Exploitation context

Available material

Curated repository PoCs
2

Affected products and versions

1
ProductSourceVersion rangeStatus

WooCommerce Affiliate Plugin – Coupon Affiliates

CVE List4.16.4.5 to < 4.16.4.5affected

Proofs of concept

2

Curated repository PoCs

GitHubCVE-2022-0818Curated repository PoCby yubsyStars: 112Not analyzed1 file

Python · 696 B

GitHub

PoC details
GitHubCVE-2022-0818Curated repository PoCby 0xd3vilStars: 127Not analyzed1 file

Python · 696 B

GitHub

PoC details

References

2