Medium severity4.3NVD Advisory· Published Nov 7, 2022· Updated Jun 17, 2026
CVE-2022-3451
CVE-2022-3451
Description
The Product Stock Manager WordPress plugin before 1.0.5 does not have authorisation and proper CSRF checks in multiple AJAX actions, allowing users with a role as low as subscriber to call them. One action in particular could allow to update arbitrary options
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- WordPress/Product Stock Managerdescription
- Range: <1.0.5
- cpe:2.3:a:addify:product_stock_manager:*:*:*:*:*:wordpress:*:*Range: <1.0.5
Patches
Vulnerability mechanics
References
1- wpscan.com/vulnerability/d8005cd0-8232-4d43-a4e4-14728eaf1300nvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.