| |
Vulnerability CVE-2022-1570
Published: 2022-06-08
Description: |
The Files Download Delay WordPress plugin before 1.0.7 does not have authorisation and CSRF checks when reseting its settings, which could allow any authenticated users, such as subscriber to perform such action. |
Type:
CWE-862 (Missing Authorization)
CVSS2 => (AV:N/AC:L/Au:S/C:N/I:P/A:N)
CVSS Base Score |
Impact Subscore |
Exploitability Subscore |
4/10 |
2.9/10 |
8/10 |
Exploit range |
Attack complexity |
Authentication |
Remote |
Low |
Single time |
Confidentiality impact |
Integrity impact |
Availability impact |
None |
Partial |
None |
References: |
https://wpscan.com/vulnerability/c0257564-48ee-4d02-865f-82c8b5e793c9
|
|
|
closedb();
?>
Copyright 2024, cxsecurity.com
|
|
|