// For flags

CVE-2022-2223

Image Slider <= 1.1.121 - Cross-Site Request Forgery to Post Duplication

Severity Score

4.3
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

The WordPress plugin Image Slider is vulnerable to Cross-Site Request Forgery in versions up to, and including 1.1.121 due to failure to properly check for the existence of a nonce in the function ewic_duplicate_slider. This make it possible for unauthenticated attackers to duplicate existing posts or pages granted they can trick a site administrator into performing an action such as clicking on a link.

El plugin Image Slider de WordPress es vulnerable a un ataque de tipo Cross-Site Request Forgery en versiones hasta 1.1.121 incluyéndola, debido a que no es comprobada apropiadamente la existencia de un nonce en la función ewic_duplicate_slider. Esto hace posible que atacantes no autenticados dupliquen publicaciones o páginas existentes concedidas pueden engañar a un administrador del sitio para que lleve a cabo una acción como hacer clic en un enlace

*Credits: Marco Wotschka
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Unchanged
Confidentiality
None
Integrity
Low
Availability
None
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Unchanged
Confidentiality
Low
Integrity
Low
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2022-05-24 CVE Published
  • 2022-06-27 CVE Reserved
  • 2024-02-08 EPSS Updated
  • 2024-08-03 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-352: Cross-Site Request Forgery (CSRF)
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Ghozylab
Search vendor "Ghozylab"
Image Slider
Search vendor "Ghozylab" for product "Image Slider"
<= 1.1.121
Search vendor "Ghozylab" for product "Image Slider" and version " <= 1.1.121"
wordpress
Affected