CVE-2022-41135
WordPress Modula plugin <= 2.6.9 - Unauth. Plugin Settings Change vulnerability
Severity Score
5.3
*CVSS v3.1
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
Unauth. Plugin Settings Change vulnerability in Modula plugin <= 2.6.9 on WordPress.
Vulnerabilidad de Plugin Settings Change no autenticada en el complemento Modula en versiones <= 2.6.9 en WordPress.
The Customizable WordPress Gallery Plugin – Modula Image Gallery plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the update_troubleshooting_options function in versions up to, and including, 2.6.9. This makes it possible for unauthenticated attackers to update some of the plugin's options. Cross-Site Request Forgery protection was also missing.
*Credits:
Vulnerability discovered by Tien Nguyen Anh (Patchstak Alliance)
CVSS Scores
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2022-09-27 CVE Reserved
- 2022-10-28 CVE Published
- 2024-05-20 EPSS Updated
- 2024-09-16 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-284: Improper Access Control
- CWE-862: Missing Authorization
CAPEC
References (1)
URL | Tag | Source |
---|---|---|
https://patchstack.com/database/vulnerability/modula-best-grid-gallery/wordpress-modula-plugin-2-6-9-unauth-plugin-settings-change-vulnerability?_s_id=cve | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Wpchill Search vendor "Wpchill" | Customizable Wordpress Gallery Plugin - Modula Image Gallery Search vendor "Wpchill" for product "Customizable Wordpress Gallery Plugin - Modula Image Gallery" | < 2.6.91 Search vendor "Wpchill" for product "Customizable Wordpress Gallery Plugin - Modula Image Gallery" and version " < 2.6.91" | wordpress |
Affected
|