vulnerability
WordPress Plugin: yikes-inc-easy-custom-woocommerce-product-tabs: CVE-2022-28666: Missing Authorization
| Severity | CVSS | Published | Added | Modified |
|---|---|---|---|---|
| 7 | (AV:N/AC:L/Au:S/C:P/I:P/A:P) | Jun 28, 2022 | May 15, 2025 | Jul 9, 2025 |
Severity
7
CVSS
(AV:N/AC:L/Au:S/C:P/I:P/A:P)
Published
Jun 28, 2022
Added
May 15, 2025
Modified
Jul 9, 2025
Description
The WordPress plugin Custom Product Tabs for WooCommerce is vulnerable to unauthenticated options update due to lack of authorization in the register_rest_route function in versions up to, and including 1.7.7. This allows an attacker to change the plugin's options.
Solution
yikes-inc-easy-custom-woocommerce-product-tabs-plugin-cve-2022-28666
NEW
Explore Exposure Command
Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.