vulnrichment
vulnrichment copied to clipboard
CVE-2023-6892 Incorrect CPE, Vendor, Product, and Version
The CISA ADP has the wrong CPE/vendor/product for CVE-2023-6892. The vendor and product should be wpfactory and ean_for_woocommerce respectively. This is a different product from woocommerce:
- https://wordpress.org/plugins/ean-for-woocommerce/#description
- https://wordpress.org/plugins/woocommerce/
EAN for WooCommerce also has an existing CPE (see https://nvd.nist.gov/vuln/detail/CVE-2023-0062) so I swapped that in. Finally, the versions array said "*" or all versions are affected despite the CNA providing a reasonable version array. I've swapped in the CNA array.