CVE-2022-4016 describes a Cross-Site Request Forgery (CSRF) vulnerability affecting the Booster for WooCommerce, Booster Plus for WooCommerce, and Booster Elite for WooCommerce WordPress plugins prior to versions 5.6.7, 5.6.6, and 1.1.8 respectively. This medium-severity vulnerability (CVSS 6.5) allows an attacker to trick a logged-in administrator into creating or deleting arbitrary custom customer roles without their consent. There is currently no public exploit code available (Metasploit, Nuclei, ExploitDB), and the vulnerability shows no signs of active exploitation, with minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.1.8CPE matchmatch criteria | cpe:2.3:a:booster:booster_for_woocommerce:*:*:*:*:elite:wordpress:*:* | ||
< 5.6.6CPE matchmatch criteria | cpe:2.3:a:booster:booster_for_woocommerce:*:*:*:*:plus:wordpress:*:* | ||
< 5.6.7CPE matchmatch criteria | cpe:2.3:a:booster:booster_for_woocommerce:*:*:*:*:*:wordpress:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.