The Role Based Pricing for WooCommerce WordPress plugin before 1.6.3 does not have authorisation and proper CSRF checks, as well as does not validate path given via user input, allowing any authenticated users like subscriber to perform PHAR deserialization attacks when they can upload a file, and a suitable gadget chain is present on the blog
Metrics
Affected Vendors & Products
References
History
Thu, 01 May 2025 20:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|

Status: PUBLISHED
Assigner: WPScan
Published: 2022-11-07T00:00:00.000Z
Updated: 2025-05-01T19:26:42.686Z
Reserved: 2022-10-17T00:00:00.000Z
Link: CVE-2022-3536

Updated: 2024-08-03T01:14:02.420Z

Status : Modified
Published: 2022-11-07T10:15:12.093
Modified: 2025-05-01T20:15:33.907
Link: CVE-2022-3536

No data.