CVE-2022-36284
05.08.2022, 16:15
Authenticated IDOR vulnerability in StoreApps Affiliate For WooCommerce premium plugin <= 4.7.0 at WordPress allows an attacker to change the PayPal email. WooCommerce PayPal Payments plugin (free) should be at least installed to get the extra input field on the user profile page.Enginsight
| Vendor | Product | Version |
|---|---|---|
| storeapps | affiliate_for_woocommerce | 𝑥 ≤ 4.7.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References