CVE-2022-44630
The YITH WooCommerce Catalog Mode plugin before version 2.16.1 contains a cross-site request forgery vulnerability in the create_log_file function due to inadequate nonce verification. An unauthenticated attacker could exploit this flaw by tricking a site administrator into clicking a malicious link, allowing the attacker to create error or debug log files on the affected site with a filename of their choosing. This vulnerability exists in the free version of the plugin distributed on WordPress.org, while the premium versions have already been patched by the developer.
Based on public CVE data (MITRE/NVD).