CVE · Medium

CVE-2022-4016 — Booster for WooCommerce Plus [booster-plus-for-woocommerce] < 5.6.6

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2022-4016 Booster for WooCommerce Plus [booster-plus-for-woocommerce] < 5.6.6 Cross-Site Request Forgery (CSRF) Medium 6.5 < 5.6.6 5.6.6 2022-11-21

CVE-2022-4016

The Booster plugins for WordPress, including Booster, Booster Plus, and Booster Elite, contain a vulnerability that allows attackers to trick administrators into performing malicious actions. Specifically, the plugins fail to properly validate certain functions, making it possible for attackers to create and delete custom roles without proper authentication. This can be exploited through a forged request, such as a link clicked by an administrator, allowing attackers to bypass security checks and gain unauthorized access.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.