Not a U.S. government website. NDD is an independent vulnerability database by Volerion and is not affiliated with or endorsed by NIST or NVD.
VOLERION
Volerion Security Research

NOT DEFERRED DATABASE

VULNERABILITIES

CVE-2022-3154 Details

Description

The Woo Billingo Plus WordPress plugin before 4.4.5.4, Integration for Billingo & Gravity Forms WordPress plugin before 1.0.4, Integration for Szamlazz.hu & Gravity Forms WordPress plugin before 1.2.7 are lacking CSRF checks in various AJAX actions, which could allow attackers to make logged in Shop Managers and above perform unwanted actions, such as deactivate the plugin's license

Metrics

CVSS 3.x Severity and Vector Strings:

References to Advisories, Solutions, and Tools

By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.

Weakness Enumeration

CWE-IDCWE NameSource
CWE-352Cross-Site Request Forgery (CSRF)[email protected]
CWE-352Cross-Site Request Forgery (CSRF)[email protected]

Affected Products

ProductVersions
woo billingo plus project woo billingo plus
< 4.4.5.4

CPE

  • cpe:2.3:a:woo_billingo_plus_project:woo_billingo_plus:*:*:*:*:*:wordpress:*:*

Remediation

  • No remediation found in references.
integration for billingo & gravity forms project integration for billingo & gravity forms
< 1.0.4

CPE

  • cpe:2.3:a:integration_for_billingo_&_gravity_forms_project:integration_for_billingo_&_gravity_forms:*:*:*:*:*:wordpress:*:*

Remediation

  • No remediation found in references.
integration for szamlazz.hu & gravity forms project integration for szamlazz.hu & gravity forms
< 1.2.7

CPE

  • cpe:2.3:a:integration_for_szamlazz.hu_&_gravity_forms_project:integration_for_szamlazz.hu_&_gravity_forms:*:*:*:*:*:wordpress:*:*

Remediation

  • No remediation found in references.

Change History

4 change records found show changes


QUICK INFO

CVE Dictionary Entry:
CVE-2022-3154
NVD Published Date:
Oct 10, 2022
NVD Last Modified:
Jun 17, 2026
Source:
[email protected]
CVE-2022-3154 Details - Not Deferred