← back
CVE-2022-0775medium

WooCommerce < 6.2.1 - Subscriber+ Arbitrary Comment Deletion

13Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 4.3epss 0.7%
exploitation probability
0.7%top 51% of all CVEs
observed exploitation
nono source reports it
The WooCommerce WordPress plugin before 6.2.1 does not have proper authorisation check when deleting reviews, which could allow any authenticated users, such as subscriber to delete arbitrary comment
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Affected products
Unknown · WooCommerce