Vulnerability CVE-2022-3098


Published: 2022-09-26

Description:
The Login Block IPs WordPress plugin through 1.0.0 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

Type:

CWE-352

(Cross-Site Request Forgery (CSRF))

 References:
https://wpscan.com/vulnerability/f4fcf41b-c05d-4236-8e67-a52d0f94c80a

Copyright 2024, cxsecurity.com

 

Back to Top