CVE-2022-0215

Severity CVSS v4.0:
Pending analysis
Type:
CWE-352 Cross-Site Request Forgery (CSRF)
Publication date:
18/01/2022
Last modified:
24/01/2022

Description

The Login/Signup Popup, Waitlist Woocommerce ( Back in stock notifier ), and Side Cart Woocommerce (Ajax) WordPress plugins by XootiX are vulnerable to Cross-Site Request Forgery via the save_settings function found in the ~/includes/xoo-framework/admin/class-xoo-admin-settings.php file which makes it possible for attackers to update arbitrary options on a site that can be used to create an administrative user account and grant full privileged access to a compromised site. This affects versions

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:xootix:login\/signup_popup:*:*:*:*:*:wordpress:*:* 2.2 (including)
cpe:2.3:a:xootix:side_cart_woocommerce:*:*:*:*:*:wordpress:*:* 2.0 (including)
cpe:2.3:a:xootix:waitlist_woocommerce:*:*:*:*:*:wordpress:*:* 2.5.1 (including)