| |
Vulnerability CVE-2022-0404
Published: 2022-04-04
Description: |
The Material Design for Contact Form 7 WordPress plugin through 2.6.4 does not check authorization or that the option mentioned in the notice param belongs to the plugin when processing requests to the cf7md_dismiss_notice action, allowing any logged in user (with roles as low as Subscriber) to set arbitrary options to true, potentially leading to Denial of Service by breaking the site. |
Type:
CWE-863 (Incorrect Authorization)
CVSS2 => (AV:N/AC:L/Au:S/C:N/I:N/A:P)
CVSS Base Score |
Impact Subscore |
Exploitability Subscore |
4/10 |
2.9/10 |
8/10 |
Exploit range |
Attack complexity |
Authentication |
Remote |
Low |
Single time |
Confidentiality impact |
Integrity impact |
Availability impact |
None |
None |
Partial |
References: |
https://wpscan.com/vulnerability/6d0932bb-d515-4432-b67b-16aba34bd285
|
|
|
closedb();
?>
Copyright 2024, cxsecurity.com
|
|
|