CVE-2022-33201
WordPress MailerLite – Signup forms (official) plugin <= 1.5.7 - Cross-Site Request Forgery (CSRF) vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Cross-Site Request Forgery (CSRF) vulnerability in MailerLite – Signup forms (official) plugin <= 1.5.7 at WordPress allows an attacker to change the API key.
Una vulnerabilidad de falsificación de tipo Cross-Site Request Forgery (CSRF) en el plugin MailerLite - Signup forms (official) versiones anteriores a 1.5.7 incluyéndola, en WordPress permite a un atacante cambiar la clave API
The MailerLite plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.5.7. This is due to missing or incorrect nonce validation several functions used to change plugin settings. This makes it possible for unauthenticated attackers to trigger setting updates via forged request granted they can trick a site administrator into performing an action such as clicking on a link.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2022-07-22 CVE Reserved
- 2022-08-01 CVE Published
- 2024-02-22 EPSS Updated
- 2024-09-16 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-352: Cross-Site Request Forgery (CSRF)
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
https://wordpress.org/plugins/official-mailerlite-sign-up-forms/#developers | Release Notes |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Mailerlite Search vendor "Mailerlite" | Mailerlite Signup Forms Search vendor "Mailerlite" for product "Mailerlite Signup Forms" | < 1.5.8 Search vendor "Mailerlite" for product "Mailerlite Signup Forms" and version " < 1.5.8" | wordpress |
Affected
|