VYPR

Product Stock Manager

by WordPress

CVEs (1)

  • CVE-2022-3451MedNov 7, 2022
    risk 0.28cvss 4.3epss 0.00

    The Product Stock Manager WordPress plugin before 1.0.5 does not have authorisation and proper CSRF checks in multiple AJAX actions, allowing users with a role as low as subscriber to call them. One action in particular could allow to update arbitrary options