Headline
CVE-2022-41685: WordPress Integration for Szamlazz.hu & WooCommerce plugin <= 5.6.3.2 - Multiple Cross-Site Request Forgery (CSRF) vulnerabilities - Patchstack
Multiple Cross-Site Request Forgery (CSRF) vulnerabilities in Viszt Péter’s Integration for Szamlazz.hu & WooCommerce plugin <= 5.6.3.2 and Csomagpontok és szállítási címkék WooCommerce-hez plugin <= 1.9.0.2 on WordPress.
Verified
Fixed
5.4
CVSS 3.1 score Medium severity
Report
Monitoring Not reported to be exploited
Vulnerable versions
<= 5.6.3.2
PSID
792f108c7c16
Classification
Cross Site Request Forgery (CSRF)
OWASP Top 10
A5: Broken Access Control
Publicly disclosed
2022-10-20
Details
Multiple Cross-Site Request Forgery (CSRF) vulnerabilities were discovered by Lana Codes (Patchstack Alliance) in the WordPress Integration for Szamlazz.hu & WooCommerce plugin (versions <= 5.6.3.2).
Solution
Update the WordPress Integration for Szamlazz.hu & WooCommerce plugin to the latest available version (at least 5.6.3.3).
References