CRITICAL

CVE-2022-1020

CVSS v3

9.8

CRITICAL

EPSS Score

92.1%

exploit probability

CISA KEV

No

known exploited

Exploitation

SSVC status

Description

The Product Table for WooCommerce (wooproducttable) WordPress plugin before 3.1.2 does not have authorisation and CSRF checks in the wpt_admin_update_notice_option AJAX action (available to both unauthenticated and authenticated users), as well as does not validate the callback parameter, allowing unauthenticated attackers to call arbitrary functions with either none or one user controlled argument

Technical details

Published
4/18/2022

Frequently asked questions

What is CVE-2022-1020?

The Product Table for WooCommerce (wooproducttable) WordPress plugin before 3.1.2 does not have authorisation and CSRF checks in the wpt_admin_update_notice_option AJAX action (available to both unauthenticated and authenticated users), as well as does not validate the callback parameter, allowing unauthenticated attackers to call arbitrary functions with either none or one user controlled argument

Is CVE-2022-1020 actively exploited?

Active exploitation of CVE-2022-1020 has not been confirmed. The EPSS score is 92.1%, indicating the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2022-1020?

CVE-2022-1020 has a CVSS v3 base score of 9.8 (CRITICAL severity).

Is CVE-2022-1020 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.