Access Control Vulnerability in Bizswoop Account Manager for WooCommerce
CVE-2022-41656

4.3MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
27 May 2026

What is CVE-2022-41656?

A missing authorization vulnerability exists in Bizswoop Account Manager for WooCommerce, which could enable unauthorized users to exploit incorrectly configured access control security levels. This flaw allows for unauthorized actions that should be restricted to legitimate users, highlighting the importance of robust access control mechanisms to prevent security breaches.

Affected Version(s)

Account Manager for WooCommerce <= 2.1.2

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

ptsfence | Patchstack Bug Bounty Program
.