CVE-2022-2657
Estado: ModificadaMedia (4.3)—
The Multivendor Marketplace Solution for WooCommerce WordPress plugin before 3.8.12 is lacking authorisation and CSRF in multiple AJAX actions, which could allow any authenticated users, such as subscriber to call them and suspend vendors (reporter by the submitter) or update arbitrary order status (identified by WPScan when verifying the issue) for example. Other unauthenticated attacks are also possible, either directly or via CSRF
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
- Puntuación base: 4.3
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.32%
- Percentil entre todas las CVEs puntuadas: 23
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-352, CWE-862
- CWE-352, CWE-862
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2022-2657",
"cveTags": [],
"metrics": {
"cvssMetricV31": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 4.3,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N",
"integrityImpact": "LOW",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "LOW",
"confidentialityImpact": "NONE"
},
"impactScore": 1.4,
"exploitabilityScore": 2.8
}
]
},
"affected": [
{
"source": "contact@wpscan.com",
"affectedData": [
{
"vendor": "Unknown",
"product": "Multivendor Marketplace Solution for WooCommerce – WC Marketplace",
"versions": [
{
"status": "affected",
"version": "3.8.12",
"lessThan": "3.8.12",
"versionType": "custom"
}
]
}
]
}
],
"published": "2022-09-05T13:15:08.477",
"references": [
{
"url": "https://wpscan.com/vulnerability/c600dd04-f6aa-430b-aefb-c4c6d554c41a",
"tags": [
"Exploit",
"Third Party Advisory"
],
"source": "contact@wpscan.com"
},
{
"url": "https://wpscan.com/vulnerability/c600dd04-f6aa-430b-aefb-c4c6d554c41a",
"tags": [
"Exploit",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Secondary",
"source": "contact@wpscan.com",
"description": [
{
"lang": "en",
"value": "CWE-352"
},
{
"lang": "en",
"value": "CWE-862"
}
]
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-352"
},
{
"lang": "en",
"value": "CWE-862"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "The Multivendor Marketplace Solution for WooCommerce WordPress plugin before 3.8.12 is lacking authorisation and CSRF in multiple AJAX actions, which could allow any authenticated users, such as subscriber to call them and suspend vendors (reporter by the submitter) or update arbitrary order status (identified by WPScan when verifying the issue) for example. Other unauthenticated attacks are also possible, either directly or via CSRF"
},
{
"lang": "es",
"value": "El plugin Multivendor Marketplace Solution for WooCommerce de WordPress versiones anteriores a 3.8.12, carece de autorización y CSRF en múltiples acciones AJAX, lo que podría permitir a cualquier usuario autenticado, como el suscriptor, llamarlos y suspender a vendedores (reportero por el remitente) o actualizar el estado de los pedidos de forma arbitraria (identificado por WPScan cuando verifica el problema), por ejemplo. También son posibles otros ataques no autenticados, ya sea directamente o por medio de CSRF"
}
],
"lastModified": "2026-06-17T04:42:17.830",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:wc-marketplace:multivendor_marketplace_solution_for_woocommerce_-_wc_marketplace:*:*:*:*:*:wordpress:*:*",
"vulnerable": true,
"matchCriteriaId": "EAE9C855-1A9F-42A4-BD46-8995F7A51FCD",
"versionEndExcluding": "3.8.12"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "contact@wpscan.com"
}