CVE-2022-3762 is a medium-severity vulnerability affecting the Booster for WooCommerce, Booster Plus for WooCommerce, and Booster Elite for WooCommerce WordPress plugins prior to versions 5.6.7, 5.6.5, and 1.1.7 respectively. The flaw allows authenticated Shop Managers and Administrators to download arbitrary files from the server due to insufficient validation of files in certain modules, potentially leading to unauthorized information disclosure. The attack complexity is low, requiring local privileges but no user interaction. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.1.7CPE matchmatch criteria | cpe:2.3:a:booster:booster_for_woocommerce:*:*:*:*:elite:wordpress:*:* | ||
< 5.6.5CPE matchmatch criteria | cpe:2.3:a:booster:booster_for_woocommerce:*:*:*:*:plus:wordpress:*:* | ||
< 5.6.7CPE matchmatch criteria | cpe:2.3:a:booster:booster_for_woocommerce:*:*:*:*:*:wordpress:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.