6.5

CVE-2022-1967

Exploit

WP Championship < 9.3 - Multiple CSRF

wp-championship <= 9.2 - Multiple Cross-Site Request Forgery Vulnerabilities

The WP Championship WordPress plugin before 9.3 is lacking CSRF checks in various places, allowing attackers to make a logged in admin perform unwanted actions, such as create and delete arbitrary teams as well as update the plugin's settings. Due to the lack of sanitisation and escaping, it could also lead to Stored Cross-Site Scripting issues
Mögliche Gegenmaßnahme
wp-championship: Update to version 9.3, or a newer patched version
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Wp-championship ProjectWp-championship SwPlatformwordpress Version < 9.3
Weitere Schwachstelleninformationen
SystemWordPress Plugin
Produkt wp-championship
Version *-9.2
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.45% 0.356
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 6.5 2.8 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
nvd@nist.gov 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:P/A:N
CWE-352 Cross-Site Request Forgery (CSRF)

The web application does not, or can not, sufficiently verify whether a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.

https://wpscan.com/vulnerability/02d25736-c796-49bd-b774-66e0e3fcf4c9
Third Party Advisory
Exploit
https://www.wordfence.com/threat-intel/vulnerabilities/id/bd1838c4-00df-4177-84be-1f8c19ceae4e
Third Party Advisory