CVE-2022-4363
MEDIUMWholesale Market <2.2.2 & Wholesale Market for WooCommerce <2.0.1 -...
Title source: llmDescription
The Wholesale Market WordPress plugin before 2.2.2, Wholesale Market for WooCommerce WordPress plugin before 2.0.1 have a flawed CSRF check when updating their settings, which could allow attackers to make a logged in admin update them via a CSRF attack
References (1)
Core 1
Core References
Exploit, Third Party Advisory exploit
vdb-entry
technical-description
https://wpscan.com/vulnerability/734dba0b-f550-4372-884a-d42f7b0c00c7/
Scores
CVSS v3
6.5
EPSS
0.0017
EPSS Percentile
6.2%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
partial
Details
CWE
CWE-352
Status
published
Products (2)
cedcommerce/wholesale_market
< 2.2.2
cedcommerce/wholesale_market_for_woocommerce
< 2.0.1
Published
May 16, 2025
Tracked Since
Feb 18, 2026