CVE-2022-36284: WordPress Affiliate For WooCommerce premium plugin <= 4.7.0 - Authenticated IDOR vulnerability leading to PayPal email change
Authenticated IDOR vulnerability in StoreApps Affiliate For WooCommerce premium plugin <= 4.7.0 at WordPress allows an attacker to change the PayPal email. WooCommerce PayPal Payments plugin (free) should be at least installed to get the extra input field on the user profile page.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2022-36284?
The severity of CVE-2022-36284 is medium with a severity value of 6.5.
What is the description of CVE-2022-36284?
CVE-2022-36284 is an authenticated IDOR vulnerability in StoreApps Affiliate For WooCommerce plugin that allows an attacker to change the PayPal email.
What software is affected by CVE-2022-36284?
The StoreApps Affiliate For WooCommerce premium plugin version <= 4.7.0 is affected by CVE-2022-36284.
How can an attacker exploit CVE-2022-36284?
An attacker with authentication can exploit CVE-2022-36284 by changing the PayPal email.
How can I fix CVE-2022-36284?
To fix CVE-2022-36284, update the StoreApps Affiliate For WooCommerce premium plugin to a version higher than 4.7.0.