CVE-2022-1563
MEDIUMDescription
The WPGraphQL WooCommerce WordPress plugin before 0.12.4 does not prevent unauthenticated attackers from enumerating a shop's coupon codes and values via GraphQL.
Is your site exposed to CVE-2022-1563?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Affected Products
| Vendor | Product |
|---|---|
| wpengine | wpgraphql |
References
Frequently Asked Questions
What is CVE-2022-1563? +
How severe is CVE-2022-1563? +
What products are affected by CVE-2022-1563? +
How do I check if I'm vulnerable to CVE-2022-1563? +
Related Vulnerabilities
The Better Search Replace plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, …
The Genesis Blocks WordPress plugin before 3.1.3 does not properly escape data input provided to some of its blocks, allowing …
The Genesis Blocks WordPress plugin through 3.1.3 does not properly escape attributes provided to some of its custom blocks, making …
The Genesis Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Sharing block in all versions …
Cross-site scripting vulnerability exists in Advanced Custom Fields versions 6.3.5 and earlier and Advanced Custom Fields Pro versions 6.3.5 and …