CVE · High

CVE-2022-0215 — Login & Register Forms – Popup, Slider, Profile & WooCommerce [easy-login-woocommerce] < 2.3

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2022-0215 Login & Register Forms – Popup, Slider, Profile & WooCommerce [easy-login-woocommerce] < 2.3 Cross-Site Request Forgery (CSRF) High 8.8 < 2.3 2.3 2022-01-13

CVE-2022-0215

The XootiX Login/Signup Popup, Waitlist Woocommerce, and Side Cart Woocommerce plugins for WordPress contain a vulnerability that allows attackers to trick users into making unauthorized changes to site settings. This is possible due to a Cross-Site Request Forgery flaw in the save_settings function, which can be exploited to create new administrative accounts and grant full access to the affected site. The vulnerability affects multiple versions of the plugins, including the most recent ones, making it a significant security concern.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.