CVE-2022-29454
WordPress Better Messages plugin <= 1.9.9.148 - Cross-Site Request Forgery (CSRF) vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Cross-Site Request Forgery (CSRF) vulnerability in WordPlus Better Messages plugin <= 1.9.9.148 at WordPress allows attackers to upload files. File attachment to messages must be activated.
Una vulnerabilidad de tipo Cross-Site Request Forgery (CSRF) en el plugin WordPlus Better Messages versiones anteriores a 1.9.9.148 incluyéndola, en WordPress permite a atacantes subir archivos. El archivo adjunto a los mensajes debe estar activado
The Better Messages plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 19.9.148. This is due to missing nonce validation on the favorite() function. This makes it possible for unauthenticated attackers to favorite messages via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2022-01-18 CVE Published
- 2022-04-18 CVE Reserved
- 2024-09-16 CVE Updated
- 2024-09-17 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-352: Cross-Site Request Forgery (CSRF)
CAPEC
References (2)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://patchstack.com/database/vulnerability/bp-better-messages/wordpress-better-messages-plugin-1-9-9-148-cross-site-request-forgery-csrf-vulnerability | 2022-07-26 |
URL | Date | SRC |
---|---|---|
https://wordpress.org/plugins/bp-better-messages/#developers | 2022-07-26 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Wordplus Search vendor "Wordplus" | Better Messages Search vendor "Wordplus" for product "Better Messages" | < 1.9.9.149 Search vendor "Wordplus" for product "Better Messages" and version " < 1.9.9.149" | wordpress |
Affected
|