Medium severity6.5NVD Advisory· Published Dec 12, 2022· Updated Jun 17, 2026
CVE-2022-4016
CVE-2022-4016
Description
The Booster for WooCommerce WordPress plugin before 5.6.7, Booster Plus for WooCommerce WordPress plugin before 5.6.6, Booster Elite for WooCommerce WordPress plugin before 1.1.8 does not properly check for CSRF when creating and deleting Customer roles, allowing attackers to make logged admins create and delete arbitrary custom roles via CSRF attacks
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
7<1.1.8+ 1 more
- (no CPE)range: <1.1.8
- (no CPE)range: <1.1.8
- Range: <5.6.6
- Range: <5.6.7
cpe:2.3:a:booster:booster_for_woocommerce:*:*:*:*:elite:wordpress:*:*+ 2 more
- cpe:2.3:a:booster:booster_for_woocommerce:*:*:*:*:elite:wordpress:*:*range: <1.1.8
- cpe:2.3:a:booster:booster_for_woocommerce:*:*:*:*:plus:wordpress:*:*range: <5.6.6
- cpe:2.3:a:booster:booster_for_woocommerce:*:*:*:*:*:wordpress:*:*range: <5.6.7
Patches
Vulnerability mechanics
References
1- wpscan.com/vulnerability/9b77044c-fd3f-4e6f-a759-dcc3082dcbd6nvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.