Record summary

CVE-2022-28666 has a selected CVSS score of 5.3 (medium); EIP currently links 1 Nuclei template.

Description

Broken Access Control vulnerability in YIKES Inc. Custom Product Tabs for WooCommerce plugin <= 1.7.7 at WordPress leading to &yikes-the-content-toggle option update.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Jun 28, 2022 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationNone
AutomatableYes
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Feb 20, 2025 · Source: CVE List

Affected products and versions

2
ProductSourceVersion rangeStatus

Custom Product Tabs for WooCommerce (WordPress plugin)

Browse YIKES Inc. / Custom Product Tabs for WooCommerce (WordPress plugin)yikes-inc-easy-custom-woocommerce-product-tabs

Default status: unaffected

CVE ListThrough 1.7.7affected
VulnCheckVersion data not supplied

Nuclei templates

1
ProjectDiscoveryMEDIUMCustom Product Tabs for WooCommerce < 1.7.8 - Unauthenticated Toggle Content Setting UpdateCVSS 5.3

YIKES Inc. Custom Product Tabs for WooCommerce plugin \u003C= 1.7.7 contains a broken access control caused by improper permission checks in &yikes-the-content-toggle option update, letting attackers modify content without authorization.

Impact

Attackers can modify product tab content without authorization, potentially leading to content tampering or misinformation.

Remediation

Update to the latest version of the plugin, above 1.7.7.

WeaknessesCWE-287
AuthorsSourabh-Sahu
Template tagscvecve2022wordpresswp-pluginwpcustom_product_tabs_for_woocommercevkevintrusive
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
CPE: cpe:2.3:a:yikesinc:custom_product_tabs_for_woocommerce:*:*:*:*:*:wordpress:*:*

Source: ProjectDiscovery

References

4