vulnerability

WordPress Plugin: yikes-inc-easy-custom-woocommerce-product-tabs: CVE-2022-28666: Missing Authorization

Severity
7
CVSS
(AV:N/AC:L/Au:S/C:P/I:P/A:P)
Published
Jun 28, 2022
Added
May 15, 2025
Modified
Jul 9, 2025

Description

The WordPress plugin Custom Product Tabs for WooCommerce is vulnerable to unauthenticated options update due to lack of authorization in the register_rest_route function in versions up to, and including 1.7.7. This allows an attacker to change the plugin's options.

Solution

yikes-inc-easy-custom-woocommerce-product-tabs-plugin-cve-2022-28666
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.