5.4

CVE-2022-1763

Exploit

Static Page eXtended <= 2.1 - Arbitrary Settings Update via CSRF to Stored XSS

Static Page eXtended <= 2.1 - Cross-Site Request Forgery

Due to missing checks the Static Page eXtended WordPress plugin through 2.1 is vulnerable to CSRF attacks which allows changing the plugin settings, including required user levels for specific features. This could also lead to Stored Cross-Site Scripting due to the lack of escaping in some of the settings
Mögliche Gegenmaßnahme
Static Page eXtended: No known patch available. Please review the vulnerability's details in depth and employ mitigations based on your organization's risk tolerance. It may be best to uninstall the affected software and find a replacement.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Static Page Extended ProjectStatic Page Extended SwPlatformwordpress Version <= 2.1
Weitere Schwachstelleninformationen
SystemWordPress Plugin
Produkt Static Page eXtended
Version *-2.1
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.29% 0.206
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5.4 2.3 2.7
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
nvd@nist.gov 3.5 6.8 2.9
AV:N/AC:M/Au:S/C:N/I:P/A:N
CWE-352 Cross-Site Request Forgery (CSRF)

The web application does not, or can not, sufficiently verify whether a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.

https://wpscan.com/vulnerability/bd3aff73-078a-4e5a-b9e3-1604851c6df8
Third Party Advisory
Exploit
https://www.wordfence.com/threat-intel/vulnerabilities/id/a83def40-27fa-4141-bebf-f86944e4c618
Third Party Advisory