CVE-2022-25649: WordPress Affiliate For WooCommerce premium plugin <= 4.7.0 - Multiple Improper Access Control vulnerabilities
Published Aug 5, 2022
·Updated
Multiple Improper Access Control vulnerabilities in StoreApps Affiliate For WooCommerce premium plugin <= 4.7.0 at WordPress.
Affected Software
1 affected component
StoreApps Affiliate For Woocommerce Wordpress<4.8.0
Remediation
Information
Update to 4.8.0 or higher version.
Event History
Aug 5, 2022
CVE Published
via MITRE·03:07 PM
Data Sourced
via MITRE·03:07 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2022-25649?
CVE-2022-25649 has been classified with a high severity level due to its potential for unauthorized access.
2
How do I fix CVE-2022-25649?
To fix CVE-2022-25649, update the StoreApps Affiliate For WooCommerce plugin to version 4.8.0 or later.
3
What systems are affected by CVE-2022-25649?
CVE-2022-25649 affects versions of StoreApps Affiliate For WooCommerce plugin up to and including 4.7.0.
4
What are the risks of CVE-2022-25649?
The risks of CVE-2022-25649 include unauthorized access to sensitive functionalities and personal data leakage.
5
Is CVE-2022-25649 easy to exploit?
Yes, CVE-2022-25649 is considered relatively easy to exploit due to improper access control mechanisms.