CVE · High

CVE-2022-4017 — Booster for WooCommerce Plus [booster-plus-for-woocommerce] < 6.0.1

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2022-4017 Booster for WooCommerce Plus [booster-plus-for-woocommerce] < 6.0.1 Cross-Site Request Forgery (CSRF) High 8.8 < 6.0.1 6.0.1 2023-01-02

CVE-2022-4017

A vulnerability was discovered in the WordPress Booster Elite for WooCommerce plugin, which could allow an attacker to trick a higher-privileged user into performing unintended actions, such as changing a password, and subsequently gaining access to the admin account. This is due to a Cross Site Request Forgery (CSRF) issue, which can be exploited by a malicious actor. The vulnerability has been addressed in version 6.0.1 of the plugin.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.