Medium severity6.5NVD Advisory· Published Aug 22, 2022· Updated Jun 17, 2026
CVE-2022-2555
CVE-2022-2555
Description
The Yotpo Reviews for WooCommerce WordPress plugin through 2.0.4 lacks nonce check when updating its settings, which could allow attacker to make a logged in admin change them via a CSRF attack.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- cpe:2.3:a:yotpo_reviews_for_woocommerce_project:yotpo_reviews_for_woocommerce:*:*:*:*:*:wordpress:*:*Range: <=2.0.4
- WordPress/Yotpo Reviews for WooCommerce plugindescription
- Range: <=2.0.4
Patches
Vulnerability mechanics
References
1- wpscan.com/vulnerability/7ec9e493-bc48-4a5d-8c7e-34beaba892aenvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.