CVE · High

CVE-2022-3763 — Booster for WooCommerce Plus [booster-plus-for-woocommerce] < 5.6.5

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2022-3763 Booster for WooCommerce Plus [booster-plus-for-woocommerce] < 5.6.5 Cross-Site Request Forgery (CSRF) High 8.1 < 5.6.5 5.6.5 2022-10-31

CVE-2022-3763

The Booster for WooCommerce plugin for WordPress has a security flaw in versions up to 5.6.6 (Free) and 5.6.4 (Premium) that allows an attacker to delete files uploaded during checkout without being authenticated. This is because the plugin doesn't properly check whether the request to delete the file is legitimate, making it vulnerable to a type of attack called a Cross-Site Request Forgery. An attacker can exploit this vulnerability by tricking a site's Shop Manager into performing a malicious action, such as clicking on a link, which would then allow the attacker to delete the file.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.