CVE-2022-44630 MEDIUM

CVE-2022-44630: WordPress YITH WooCommerce Product Slider Carousel plugin <= 1.16.0 - Cross-Site Request Forgery (CSRF)

Vendor Yith
Product YITH WooCommerce Product Slider Carousel
Weakness CWE-352 · CSRF
Published June 11, 2026
Last update June 11, 2026

CVSS base score

4.6/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction Required
Confidentiality Low
Integrity Low

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N

What the vulnerability does

Description

Cross-Site request forgery (CSRF) vulnerability in YITH YITH WooCommerce Product Slider Carousel allows Cross Site Request Forgery. This issue affects YITH WooCommerce Product Slider Carousel: from n/a through 1.16.0.

Key dates

Disclosure timeline

June 11, 2026 CVE published
June 11, 2026 Record updated