Vulnerability Details CVE-2022-3537
The Role Based Pricing for WooCommerce WordPress plugin before 1.6.2 does not have authorisation and proper CSRF checks, and does not validate files to be uploaded, allowing any authenticated users like subscriber to upload arbitrary files, such as PHP
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 34.2%
CVSS Severity
CVSS v3 Score 8.8
Products affected by CVE-2022-3537
-
cpe:2.3:a:addify:role_based_pricing_for_woocommerce:1.0.0
-
cpe:2.3:a:addify:role_based_pricing_for_woocommerce:1.1.0
-
cpe:2.3:a:addify:role_based_pricing_for_woocommerce:1.2.0
-
cpe:2.3:a:addify:role_based_pricing_for_woocommerce:1.3.0
-
cpe:2.3:a:addify:role_based_pricing_for_woocommerce:1.3.1
-
cpe:2.3:a:addify:role_based_pricing_for_woocommerce:1.3.2
-
cpe:2.3:a:addify:role_based_pricing_for_woocommerce:1.3.3
-
cpe:2.3:a:addify:role_based_pricing_for_woocommerce:1.3.4
-
cpe:2.3:a:addify:role_based_pricing_for_woocommerce:1.3.5
-
cpe:2.3:a:addify:role_based_pricing_for_woocommerce:1.3.6
-
cpe:2.3:a:addify:role_based_pricing_for_woocommerce:1.4.0
-
cpe:2.3:a:addify:role_based_pricing_for_woocommerce:1.4.1
-
cpe:2.3:a:addify:role_based_pricing_for_woocommerce:1.4.2
-
cpe:2.3:a:addify:role_based_pricing_for_woocommerce:1.4.3
-
cpe:2.3:a:addify:role_based_pricing_for_woocommerce:1.4.4
-
cpe:2.3:a:addify:role_based_pricing_for_woocommerce:1.5.0
-
cpe:2.3:a:addify:role_based_pricing_for_woocommerce:1.5.1
-
cpe:2.3:a:addify:role_based_pricing_for_woocommerce:1.5.2
-
cpe:2.3:a:addify:role_based_pricing_for_woocommerce:1.5.3
-
cpe:2.3:a:addify:role_based_pricing_for_woocommerce:1.5.4
-
cpe:2.3:a:addify:role_based_pricing_for_woocommerce:1.5.5
-
cpe:2.3:a:addify:role_based_pricing_for_woocommerce:1.5.6
-
cpe:2.3:a:addify:role_based_pricing_for_woocommerce:1.5.7
-
cpe:2.3:a:addify:role_based_pricing_for_woocommerce:1.5.8
-
cpe:2.3:a:addify:role_based_pricing_for_woocommerce:1.5.9
-
cpe:2.3:a:addify:role_based_pricing_for_woocommerce:1.6.0
-
cpe:2.3:a:addify:role_based_pricing_for_woocommerce:1.6.1