CVE Database /
CVE-2022-0215
CVE · High
CVE-2022-0215 — Login & Register Forms – Popup, Slider, Profile & WooCommerce [easy-login-woocommerce] < 2.3
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2022-0215
|
Login & Register Forms – Popup, Slider, Profile & WooCommerce [easy-login-woocommerce] < 2.3 |
Cross-Site Request Forgery (CSRF) |
High
8.8
|
< 2.3
|
2.3 |
2022-01-13 |
—
|
CVE-2022-0215
The XootiX Login/Signup Popup, Waitlist Woocommerce, and Side Cart Woocommerce plugins for WordPress contain a vulnerability that allows attackers to trick users into making unauthorized changes to site settings. This is possible due to a Cross-Site Request Forgery flaw in the save_settings function, which can be exploited to create new administrative accounts and grant full access to the affected site. The vulnerability affects multiple versions of the plugins, including the most recent ones, making it a significant security concern.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings