Vulnerability CVE-2022-2350


Published: 2022-10-10

Description:
The Disable User Login WordPress plugin through 1.0.1 does not have authorisation and CSRF checks when updating its settings, allowing unauthenticated attackers to block (or unblock) users at will.

Type:

CWE-352

(Cross-Site Request Forgery (CSRF))

 References:
https://wpscan.com/vulnerability/de28543b-c110-4a9f-bfe9-febccfba3a96

Copyright 2026, cxsecurity.com

 

Back to Top