CVE-2022-4363
MEDIUMWholesale Market <2.2.2 & Wholesale Market for WooCommerce <2.0.1 -...
Title source: llmDescription
The Wholesale Market WordPress plugin before 2.2.2, Wholesale Market for WooCommerce WordPress plugin before 2.0.1 have a flawed CSRF check when updating their settings, which could allow attackers to make a logged in admin update them via a CSRF attack
Scores
CVSS v3
6.5
EPSS
0.0009
EPSS Percentile
25.6%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
Classification
CWE
CWE-352
Status
published
Affected Products (2)
cedcommerce/wholesale_market
< 2.2.2
cedcommerce/wholesale_market_for_woocommerce
< 2.0.1
Timeline
Published
May 16, 2025
Tracked Since
Feb 18, 2026