CVE-2022-0775


WooCommerce < 6.2.1 - Subscriber+ Arbitrary Comment Deletion

The WooCommerce WordPress plugin before 6.2.1 does not have proper authorisation check when deleting reviews, which could allow any authenticated users, such as subscriber to delete arbitrary comment



We have discovered 428,468 live websites that are affected by CVE-2022-0775.

Contact us to get more info




Affected Software

Product  WooCommerce
Category Ecommerce
Vulnerable Versions
  • from 0 before 6.2.1
Total Vulnerable Versions582
Vulnerable Domains428,468 live websites (33.16% of WooCommerce install base)


Common Weakness Enumeration


CWE-863 Incorrect Authorization



Details

  • Published - Jan 16, 2024
  • Updated - Jan 16, 2024

Credits

  • Krzysztof Zając (finder)
  • WPScan (coordinator)





Countries

United States103,425 websites



Italy23,149 websites
Germany22,958 websites
France22,811 websites
Russia20,541 websites
GB19,929 websites
Spain15,105 websites
Vietnam13,977 websites
Netherlands11,774 websites
Australia10,233 websites

TLDs

.com193,410 websites
.ru16,068 websites
.it14,877 websites
.co.uk11,562 websites
.de10,909 websites
.org10,865 websites
.nl8,960 websites
.fr8,372 websites
.net8,220 websites
.com.br7,814 websites

Vulnerable Versions

Vulnerable versions are highlighted in red


References


Websites affected by CVE-2022-0775

Top websites that are affected by CVE-2022-0775. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
***.***.com United States*,***
***.***********.com Italy*,***
***********.com United States*,***
*****************.com United States*,***
***.*************.com United States*,***
***.com United States*,***
*********.com United States*,***
*******.com United States*,***
***.**********.com United States*,***
*********.com Netherlands**,***
See full domain list