The Wholesale Market WordPress plugin before 2.2.2, Wholesale Market for WooCommerce WordPress plugin before 2.0.1 have a flawed CSRF check when updating their settings, which could allow attackers to make a logged in admin update them via a CSRF attack
| Software | From | Fixed in |
|---|---|---|
| cedcommerce / wholesale_market | - | 2.2.2 |
| cedcommerce / wholesale_market_for_woocommerce | - | 2.0.1 |