CVE-2022-4872

CVE-2022-4872: WooCommerce Chained Products < 2.12.0 - Unauthenticated Arbitrary Options Update to 'no'

Vendor Unknown
Product Chained Products
Published January 30, 2023
Last update March 27, 2025

CVSS base score

What the vulnerability does

01Description

The Chained Products WordPress plugin before 2.12.0 does not have authorisation and CSRF checks, as well as does not ensure that the option to be updated belong to the plugin, allowing unauthenticated attackers to set arbitrary options to 'no'

Key dates

02Disclosure timeline

January 30, 2023 CVE published
March 27, 2025 Record updated