PoC Index

CVE-2022-28666

MEDIUM 5.3EPSS 1.4%

Broken Access Control vulnerability in YIKES Inc. Custom Product Tabs for WooCommerce plugin <= 1.7.7 at WordPress leading to &yikes-the-content-toggle option update.

CVSS v3.1
5.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
CVSS v3.1
5.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
EPSS
1.37% chance of exploitation in the next 30 days, 70th percentile
Nuclei
medium · CWE-287
Published
2022-07-21
Updated
2026-04-28

Nuclei templates (1)

References

Related