Headline
CVE-2022-45066: WordPress WooSwipe WooCommerce Gallery plugin <= 2.0.1 - Auth. Broken Access Control vulnerability - Patchstack
Auth. (subscriber+) Broken Access Control vulnerability in WooSwipe WooCommerce Gallery plugin <= 2.0.1 on WordPress.
Verified
Not fixed
5.4
CVSS 3.1 score Medium severity
Report
Monitoring Not reported to be exploited
Software
WooSwipe WooCommerce Gallery
Vulnerable versions
<= 2.0.1
PSID
9988c66f9611
Classification
Other Vulnerability Type
OWASP Top 10
A5: Broken Access Control
Required privilege
Requires subscriber or higher role user authentication.
Publicly disclosed
2022-11-17
Details
Auth. Broken Access Control vulnerability leading to plugin settings change discovered by Tien Nguyen Anh (Patchstack Alliance) in the WordPress WooSwipe WooCommerce Gallery plugin (versions <= 2.0.1).
Solution
No patched version is available. No reply from the vendor.
References