CVE · Medium

CVE-2022-44630 — YITH WooCommerce Catalog Mode [yith-woocommerce-catalog-mode] < 2.16.1

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2022-44630 YITH WooCommerce Catalog Mode [yith-woocommerce-catalog-mode] < 2.16.1 Cross-Site Request Forgery (CSRF) Medium 4.6 < 2.16.1 2.16.1 2022-11-11

CVE-2022-44630

The YITH WooCommerce Catalog Mode plugin before version 2.16.1 contains a cross-site request forgery vulnerability in the create_log_file function due to inadequate nonce verification. An unauthenticated attacker could exploit this flaw by tricking a site administrator into clicking a malicious link, allowing the attacker to create error or debug log files on the affected site with a filename of their choosing. This vulnerability exists in the free version of the plugin distributed on WordPress.org, while the premium versions have already been patched by the developer.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.