CVE-2022-0775

WooCommerce < 6.2.1 - Subscriber+ Arbitrary Comment Deletion

The WooCommerce WordPress plugin before 6.2.1 does not have proper authorisation check when deleting reviews, which could allow any authenticated users, such as subscriber to delete arbitrary comment


We have discovered 227,926 live websites that are affected by CVE-2022-0775.

Run a Free Instant Scan




Affected Software

Product  WooCommerce
Category Ecommerce
Vulnerable Domains227,926 live websites (17% of WooCommerce install base)
Vulnerable Versions
  • from 0 through 6.2.1
Vulnerable Versions Count270 versions ( 63% of all versions)


Common Weakness Enumeration

CWE-863 Incorrect Authorization



Details

  • Published - Jan 16, 2024
  • Updated - Jun 11, 2025

Credits

  • Krzysztof Zając (finder)
  • WPScan (coordinator)

Website Distribution by Country

Number of websites using CVE-2022-0775
United States53,915 websites



Germany15,408 websites
Italy12,702 websites
France12,476 websites
Russia12,154 websites
GB11,405 websites
Spain7,752 websites
Vietnam7,446 websites
Netherlands6,297 websites
Poland5,161 websites

Website Distribution by TLD

Number of websites using CVE-2022-0775
.com98,435 websites
.ru9,545 websites
.it8,496 websites
.co.uk7,040 websites
.de5,848 websites
.org5,413 websites
.nl5,133 websites
.fr4,429 websites
.net4,323 websites
.com.au3,982 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2022-0775

Top websites that are affected by CVE-2022-0775. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
***********.com United States*,***
*****************.com United States*,***
*************.com United States*,***
*********.com United States*,***
**********.com United States*,***
*********.com Netherlands**,***
********.gr Greece**,***
************.com United States**,***
*************.net Vietnam**,***
**************.com United States**,***
See full domain list

FAQ

CVE-2022-0775 is Incorrect Authorization in WooCommerce
A total of 227,926 websites have been identified as vulnerable to CVE-2022-0775, based on global website indexing conducted by WebTechSurvey.
The WooCommerce is affected by the CVE-2022-0775 vulnerability.
WooCommerce versions up to 6.2.1 are vulnerable to CVE-2022-0775.
CVE-2022-0775 is resolved in version 6.2.1 of WooCommerce.