Vulnerability CVE-2022-1761


Published: 2022-06-13

Description:
The Peter??????s Collaboration E-mails WordPress plugin through 2.2.0 is vulnerable to CSRF due to missing nonce checks. This allows the change of its settings, which can be used to lower the required user level, change texts, the used email address and more.

Type:

CWE-352

(Cross-Site Request Forgery (CSRF))

CVSS2 => (AV:N/AC:M/Au:N/C:N/I:P/A:N)

CVSS Base Score
Impact Subscore
Exploitability Subscore
4.3/10
2.9/10
8.6/10
Exploit range
Attack complexity
Authentication
Remote
Medium
No required
Confidentiality impact
Integrity impact
Availability impact
None
Partial
None
Affected software
Peter\'s collaboration e-mails project -> Peter\'s collaboration e-mails 

 References:
https://wpscan.com/vulnerability/31b413e1-d4b5-463e-9910-37876881c062

Copyright 2024, cxsecurity.com

 

Back to Top