CVE Database /
CVE-2022-43481
CVE · Medium
CVE-2022-43481 — Advanced Coupons for WooCommerce Coupons & Store Credit [advanced-coupons-for-woocommerce-free] < 4.5.0.1
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2022-43481
|
Advanced Coupons for WooCommerce Coupons & Store Credit [advanced-coupons-for-woocommerce-free] < 4.5.0.1 |
Cross-Site Request Forgery (CSRF) |
Medium
5.4
|
< 4.5.0.1
|
4.5.0.1 |
2022-10-30 |
—
|
CVE-2022-43481
The Advanced Coupons for WooCommerce plugin through version 4.5 contains a cross-site request forgery vulnerability affecting the get_all_admin_notices function, which fails to properly validate nonces. An unauthenticated attacker could exploit this flaw to conceal administrative notices by deceiving a site administrator into clicking a malicious link. The vulnerability allows attackers without authentication to manipulate the visibility of admin notices on vulnerable installations.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings