← back
CVE-2022-28666mediumobserved exploitationCWE-287

WordPress Custom Product Tabs for WooCommerce plugin <= 1.7.7 - Broken Access Control vulnerability

50Vexday Risk Score

Patch now. It exploitation observed by VulnCheck and has a working public exploit.

ssvc Actcvss 5.3epss 1.4%
from disclosure to weapon
Published on NVDJul 21
VulnCheckJun 28
exploitation probability
1.4%top 29% of all CVEs
observed exploitation
yesVulnCheck
Broken Access Control vulnerability in YIKES Inc. Custom Product Tabs for WooCommerce plugin <= 1.7.7 at WordPress leading to &yikes-the-content-toggle option update.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N