Junglewise Threat Intelligence

CVE-2022-44630: YITH WooCommerce Product Slider Carousel CSRF

CVE-2022-44630 · Severity: medium · CVSS 4.6 · Published 2026-06-11

Vendors: YITH.

Executive brief

The YITH WooCommerce Product Slider Carousel plugin for WordPress, which allows store owners to display products in an interactive slider, is vulnerable to a security flaw. An attacker could trick a logged-in administrator or authorized user into performing unintended actions on the website, such as changing plugin settings. This could lead to unauthorized modifications of the site's appearance or configuration if a user clicks on a malicious link while logged in.

Technical details

A Cross-Site Request Forgery (CSRF) vulnerability exists in the YITH WooCommerce Product Slider Carousel plugin for WordPress (versions <= 1.16.0). The issue stems from a lack of proper nonce validation on sensitive administrative actions. An attacker can exploit this by crafting a malicious request and tricking a privileged user into executing it via social engineering (e.g., a malicious link). Successful exploitation allows the attacker to perform unauthorized actions with the permissions of the victim user, such as modifying plugin settings. The vulnerability is addressed in version 1.16.1.

Affected products

  • YITH YITH WooCommerce Product Slider Carousel <= 1.16.0

Timeline

  • 2022-11-02: disclosed: Reported by István Márton
  • 2023-03-03: advisory: Patchstack published advisory
  • 2023-03-03: patched: Version 1.16.1 released

References