The WooCommerce WordPress plugin before 6.2.1 does not have proper authorisation check when deleting reviews, which could allow any authenticated users, such as subscriber to delete arbitrary comment
We have discovered 227,926 live websites that are affected by CVE-2022-0775.
| Product | |
| Category | Ecommerce |
| Vulnerable Domains | 227,926 live websites (17% of WooCommerce install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 270 versions ( 63% of all versions) |
| 53,915 websites | |
| 15,408 websites | |
| 12,702 websites | |
| 12,476 websites | |
| 12,154 websites | |
| 11,405 websites | |
| 7,752 websites | |
| 7,446 websites | |
| 6,297 websites | |
| 5,161 websites |
| .com | 98,435 websites |
| .ru | 9,545 websites |
| .it | 8,496 websites |
| .co.uk | 7,040 websites |
| .de | 5,848 websites |
| .org | 5,413 websites |
| .nl | 5,133 websites |
| .fr | 4,429 websites |
| .net | 4,323 websites |
| .com.au | 3,982 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| ***********.com | *,*** | ||
| *****************.com | *,*** | ||
| *************.com | *,*** | ||
| *********.com | *,*** | ||
| **********.com | *,*** | ||
| *********.com | **,*** | ||
| ********.gr | **,*** | ||
| ************.com | **,*** | ||
| *************.net | **,*** | ||
| **************.com | **,*** |
FAQ