| |
Vulnerability CVE-2022-3451
Published: 2022-11-07
| Description: |
The Product Stock Manager WordPress plugin before 1.0.5 does not have authorisation and proper CSRF checks in multiple AJAX actions, allowing users with a role as low as subscriber to call them. One action in particular could allow to update arbitrary options |
Type:
CWE-352 (Cross-Site Request Forgery (CSRF))
References: |
https://wpscan.com/vulnerability/d8005cd0-8232-4d43-a4e4-14728eaf1300
|
|
|
closedb();
?>
Copyright 2026, cxsecurity.com
|
|
|