CVE · Medium

CVE-2022-46794 — Weight Based Shipping for WooCommerce [weight-based-shipping-for-woocommerce] < 5.5.0

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2022-46794 Weight Based Shipping for WooCommerce [weight-based-shipping-for-woocommerce] < 5.5.0 Cross-Site Request Forgery (CSRF) Medium 4.3 < 5.5.0 5.5.0 2023-03-13

CVE-2022-46794

The WooCommerce Weight Based Shipping plugin for WordPress contains a security flaw that allows an attacker to trick a site administrator into performing certain actions. Specifically, the plugin fails to properly verify that a request is legitimate, making it possible for an attacker to create or delete shipping rules without proper authorization. This vulnerability can be exploited by an attacker who can trick a site administrator into clicking on a malicious link, allowing the attacker to manipulate the plugin's settings.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.