← Back to CVE List

CVE-2022-36284

Published: 2022-08-05T16:15Z
Last Modified: 2025-02-20T21:15Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
Authenticated IDOR vulnerability in StoreApps Affiliate For WooCommerce premium plugin <= 4.7.0 at WordPress allows an attacker to change the PayPal email. WooCommerce PayPal Payments plugin (free) should be at least installed to get the extra input field on the user profile page. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt