CVE-2022-28666
WordPress Custom Product Tabs for WooCommerce plugin <= 1.7.7 - Broken Access Control vulnerability
Record summary
CVE-2022-28666 has a selected CVSS score of 5.3 (medium); EIP currently links 1 Nuclei template.
Description
Broken Access Control vulnerability in YIKES Inc. Custom Product Tabs for WooCommerce plugin <= 1.7.7 at WordPress leading to &yikes-the-content-toggle option update.
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Jun 28, 2022 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Feb 20, 2025 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
Custom Product Tabs for WooCommerce (WordPress plugin)Browse YIKES Inc. / Custom Product Tabs for WooCommerce (WordPress plugin)yikes-inc-easy-custom-woocommerce-product-tabsDefault status: unaffected | CVE List | Through 1.7.7 | affected |
custom_product_tabs_for_woocommerceBrowse yikesinc / custom_product_tabs_for_woocommerce | VulnCheck | Version data not supplied | |
Nuclei templates
1ProjectDiscoveryMEDIUMCustom Product Tabs for WooCommerce < 1.7.8 - Unauthenticated Toggle Content Setting UpdateCVSS 5.3
YIKES Inc. Custom Product Tabs for WooCommerce plugin \u003C= 1.7.7 contains a broken access control caused by improper permission checks in &yikes-the-content-toggle option update, letting attackers modify content without authorization.
Impact
Attackers can modify product tab content without authorization, potentially leading to content tampering or misinformation.
Remediation
Update to the latest version of the plugin, above 1.7.7.
Source: ProjectDiscovery