7.1

CVE-2022-4745

Exploit

WP Customer Area < 8.1.4 - Unauthorised Actions via CSRF

WP Customer Area <= 8.1.3 - Cross-Site Request Forgery

The WP Customer Area WordPress plugin before 8.1.4 does not have CSRF checks when performing some actions such as chmod, mkdir and copy, which could allow attackers to make a logged-in admin perform them and create arbitrary folders, copy file for example.
Mögliche Gegenmaßnahme
WP Customer Area: Update to version 8.1.4, or a newer patched version
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Wp-customerareaWp Customer Area SwPlatformwordpress Version < 8.1.4
Weitere Schwachstelleninformationen
SystemWordPress Plugin
Produkt WP Customer Area
Version *-8.1.3
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.28% 0.191
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.1 2.8 4.2
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N
134c704f-9b21-4f2e-91b3-4a467353bcc0 6.1 2.8 2.7
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://wpscan.com/vulnerability/9703f42e-bdfe-4787-92c9-47963d9af425
Third Party Advisory
Exploit
https://www.wordfence.com/threat-intel/vulnerabilities/id/ad5aeea0-ba5a-488a-9087-9b7567f31c70
Third Party Advisory