CVE-2022-0952
Sitemap by click5 < 1.0.36 - Unauthenticated Arbitrary Options Update
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
2Exploited in Wild
-Decision
Descriptions
The Sitemap by click5 WordPress plugin before 1.0.36 does not have authorisation and CSRF checks when updating options via a REST endpoint, and does not ensure that the option to be updated belongs to the plugin. As a result, unauthenticated attackers could change arbitrary blog options, such as the users_can_register and default_role, allowing them to create a new admin account and take over the blog.
El plugin Sitemap by click5 de WordPress versiones anteriores a 1.0.36, no dispone de comprobaciones de autorización y de tipo CSRF cuando son actualizadas las opciones por medio de un endpoint REST, y no es asegurado de que la opción que va a actualizarse pertenezca al plugin. Como resultado, atacantes no autenticados podrían cambiar opciones arbitrarias del blog, como users_can_register y default_role, permitiéndoles crear una nueva cuenta de administrador y tomar el control del blog
CVSS Scores
SSVC
- Decision:-
Timeline
- 2022-03-14 CVE Reserved
- 2022-04-13 CVE Published
- 2023-08-09 First Exploit
- 2024-08-02 CVE Updated
- 2024-11-10 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-352: Cross-Site Request Forgery (CSRF)
- CWE-862: Missing Authorization
CAPEC
References (2)
URL | Tag | Source |
---|
URL | Date | SRC |
---|---|---|
https://github.com/RandomRobbieBF/CVE-2022-0952 | 2023-08-09 | |
https://wpscan.com/vulnerability/0f694961-afab-44f9-846c-e80a0f6c768b | 2024-08-02 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Sitemap Project Search vendor "Sitemap Project" | Sitemap Search vendor "Sitemap Project" for product "Sitemap" | < 1.0.36 Search vendor "Sitemap Project" for product "Sitemap" and version " < 1.0.36" | wordpress |
Affected
|