CVE-2022-1020
9.8
CRITICAL · CVSS 3.1 · EPSS 25.9% (pctl 98)
Patch early
EPSS 25.9% — above the 10% action threshold.
Description
The Product Table for WooCommerce (wooproducttable) WordPress plugin before 3.1.2 does not have authorisation and CSRF checks in the wpt_admin_update_notice_option AJAX action (available to both unauthenticated and authenticated users), as well as does not validate the callback parameter, allowing unauthenticated attackers to call arbitrary functions with either none or one user controlled argument
Scoring
| CVSS | 9.8 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 25.94% — more likely to be exploited than 98% of all CVEs |
| Weakness | CWE-352 |
| On CISA KEV | no |
| Public exploit | none known |
| Published | 2022-04-18 |
| Last modified | 2026-06-17 |
Affected (1)
| Vendor | Product |
|---|---|
| codeastrology | woo product table |
References
→ the Explorer · watch your stack · NVD