CVE-2022-3750 – Ask Me < 6.8.7 - Post Deletion via CSRF
https://notcve.org/view.php?id=CVE-2022-3750
The has a CSRF vulnerability that allows the deletion of a post without using a nonce or prompting for confirmation. Tiene una vulnerabilidad CSRF que permite eliminar una publicación sin utilizar un nonce ni solicitar confirmación. The Ask Me theme for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, but not including, 6.8.7. This is due to missing or incorrect nonce validation on one of its functions. This makes it possible for unauthenticated attackers to invoke that function, via forged request granted they can trick a site administrator into performing an action such as clicking on a link. • https://wpscan.com/vulnerability/5019db80-0356-497d-b488-a26a5de78676 • CWE-352: Cross-Site Request Forgery (CSRF) •
CVE-2022-1251 – Ask Me < 6.8.4 - CSRF in Edit Profile
https://notcve.org/view.php?id=CVE-2022-1251
The Ask me WordPress theme before 6.8.4 does not perform nonce checks when processing POST requests to the Edit Profile page, allowing an attacker to trick a user to change their profile information by sending a crafted request. El tema Ask me de WordPress versiones anteriores a 6.8.4, no lleva a cabo comprobaciones de nonce cuando procesa peticiones POST a la página Edit Profile, lo que permite a un atacante engañar a un usuario para que cambie su información de perfil mediante el envío de una petición diseñada. The Ask Me theme for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 6.8.3. This is due to missing or incorrect nonce validation when editing profiles. This makes it possible for unauthenticated attackers to edit user profiles, via forged request granted they can trick a site administrator into performing an action such as clicking on a link. • https://wpscan.com/vulnerability/34b3fc35-381a-4bd7-87e3-f1ef0a15a349 • CWE-352: Cross-Site Request Forgery (CSRF) •
CVE-2022-1241 – Ask Me < 6.8.2 - Reflected Cross-Site Scripting
https://notcve.org/view.php?id=CVE-2022-1241
The Ask me WordPress theme before 6.8.2 does not properly sanitise and escape several of the fields in the Edit Profile page, leading to Reflected Cross-Site Scripting issues El tema Ask me de WordPress versiones anteriores a 6.8.2, no sanea ni escapa apropiadamente de varios campos de la página Edit Profile, lo que conlleva problemas de Reflected Cross-Site Scripting • https://wpscan.com/vulnerability/3258393a-eafb-4356-994e-2ff8ce223c9b • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2022-1424 – Ask Me < 6.8.2 - Multiple CSRF in AJAX Actions
https://notcve.org/view.php?id=CVE-2022-1424
The Ask me WordPress theme before 6.8.2 does not perform CSRF checks for any of its AJAX actions, allowing an attacker to trick logged in users to perform various actions on their behalf on the site. El tema Ask me de WordPress versiones anteriores a 6.8.2, no lleva a cabo comprobaciones de tipo CSRF para ninguna de sus acciones AJAX, lo que permite a un atacante engañar a usuarios registrados para que lleven a cabo varias acciones en su nombre en el sitio • https://wpscan.com/vulnerability/147b4097-dec8-4542-b122-7b237db81c05 • CWE-352: Cross-Site Request Forgery (CSRF) •