MIRAGE
Threat IntelligenceCVEs › CVE-2022-1020

CVE-2022-1020 — exposed on the internet

Internet exposure observed by OffSeq scans · last 30 days

1
Exposed hosts
9.8
CVSS
25.9%
EPSS

Found on 1 internet-exposed hosts by OffSeq scans; no in-the-wild exploitation has been observed against OffSeq honeypots in this window.

About CVE-2022-1020

The Product Table for WooCommerce (wooproducttable) WordPress plugin before 3.1.2 does not have authorisation and CSRF checks in the wpt_admin_update_notice_option AJAX action (available to both unauthenticated and authenticated users), as well as does not validate the callback parameter, allowing unauthenticated attackers to call arbitrary functions with either none or one user controlled argument

CWE-352CWE-862

OffSeq internet scanning found CVE-2022-1020 on 1 exposed hosts in the last 30 days. OffSeq honeypots have not recorded in-the-wild exploitation of this CVE in the current window — this page tracks its exposure footprint and status; if exploitation begins, the live honeypot signal will appear here.

Exposed-host countries

Exposed via

wordpress

Open the live CVE-2022-1020 view →

References