CVE-2022-3999

CVE-2022-3999: WooCommerce Shipping - DPD baltic < 1.2.57 - Subscriber+ Arbitrary Options Deletion

Vendor Unknown
Product DPD Baltic Shipping
Published December 12, 2022
Last update April 22, 2025

CVSS base score

What the vulnerability does

01Description

The DPD Baltic Shipping WordPress plugin before 1.2.57 does not have authorisation and CSRF in an AJAX action, which could allow any authenticated users, such as subscriber to delete arbitrary options from the blog, which could make the blog unavailable.

Key dates

02Disclosure timeline

December 12, 2022 CVE published
April 22, 2025 Record updated