// For flags

CVE-2022-33969

WordPress Flipbox plugin <= 2.6.0 - Authenticated WordPress Options Change vulnerability

Time Line
Published
2024-03-19
Updated
2024-03-19
Firt exploit
2024-03-19
Overview
Descriptions (3)
NVD, NVD, Wordfence
CWE (2)
CWE-264: Permissions, Privileges, and Access Controls
CWE-639: Authorization Bypass Through User-Controlled Key
CAPEC (-)
Risk
CVSS Score
7.2 High
SSVC
Track*
KEV
-
EPSS
0.1%
Affected Products (-)
Vendors (1)
oxilab
Products (1)
flipbox
Versions (1)
<= 2.6.0
Intel Resources (-)
Advisories (-)
-
Exploits (-)
-
Plugins (-)
-
References (2)
General (2)
patchstack, wordpress
Exploits & POcs (-)
Patches (-)
Advisories (-)
Summary
Descriptions

Authenticated WordPress Options Change vulnerability in Biplob Adhikari's Flipbox plugin <= 2.6.0 at WordPress.

Una vulnerabilidad de Cambio de Opciones de WordPress Autenticado en el plugin Flipbox de Biplob Adhikari versiones anteriores a 2.6.0 incluyéndola en WordPress

The Flipbox – Awesomes Flip Boxes Image Overlay plugin for WordPress is vulnerable to arbitrary options updates in versions up to, and including, 2.6.0. This is due to a lack of validation on the settings supplied to the oxi_settings() function. This makes it possible for authenticated attackers, with administrative level permissions, to update arbitrary options on the WordPress site. This would only affect sites where the administrator has been restricted to not 'manage_options' or the administrator has allowed users with lower permissions to update the plugin's settings.

*Credits: Vulnerability discovered by m0ze (Patchstack)
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
High
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Attack Vector
Network
Attack Complexity
Low
Authentication
Multiple
Confidentiality
Complete
Integrity
Complete
Availability
Complete
* Common Vulnerability Scoring System
SSVC
  • Decision:Track*
Exploitation
None
Automatable
No
Tech. Impact
Total
* Organization's Worst-case Scenario
Timeline
  • 2022-07-22 CVE Reserved
  • 2022-07-25 CVE Published
  • 2024-02-15 EPSS Updated
  • 2025-02-20 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-264: Permissions, Privileges, and Access Controls
  • CWE-639: Authorization Bypass Through User-Controlled Key
CAPEC
Threat Intelligence Resources (0)
Security Advisory details:

Select an advisory to view details here.

Select an exploit to view details here.

Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Oxilab
Search vendor "Oxilab"
Flipbox
Search vendor "Oxilab" for product "Flipbox"
<= 2.6.0
Search vendor "Oxilab" for product "Flipbox" and version " <= 2.6.0"
wordpress
Affected