Authenticated IDOR vulnerability in StoreApps Affiliate For WooCommerce premium plugin <= 4.7.0 at WordPress allows an attacker to change the PayPal email. WooCommerce PayPal Payments plugin (free) should be at least installed to get the extra input field on the user profile page.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: Patchstack

Published: 2022-08-01T00:00:00

Updated: 2022-08-05T15:08:51

Reserved: 2022-07-22T00:00:00


Link: CVE-2022-36284

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2022-08-05T16:15:14.557

Modified: 2022-08-10T16:59:54.663


Link: CVE-2022-36284

JSON object: View

cve-icon Redhat Information

No data.

CWE