CVE-2022-3536
HIGHWooCommerce WordPress <1.6.3 - Code Injection
Title source: llmDescription
The Role Based Pricing for WooCommerce WordPress plugin before 1.6.3 does not have authorisation and proper CSRF checks, as well as does not validate path given via user input, allowing any authenticated users like subscriber to perform PHAR deserialization attacks when they can upload a file, and a suitable gadget chain is present on the blog
Scores
CVSS v3
8.8
EPSS
0.0008
EPSS Percentile
24.5%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Classification
CWE
CWE-502
CWE-352
Status
published
Affected Products (1)
addify/role_based_pricing_for_woocommerce
< 1.6.3
Timeline
Published
Nov 07, 2022
Tracked Since
Feb 18, 2026