// For flags

CVE-2022-42459

WordPress Image Hover Effects Ultimate plugin <= 9.7.1 - Auth. WordPress Options Change vulnerability

Time Line
Published
2024-03-19
Updated
2024-03-19
Firt exploit
2024-03-19
Overview
Descriptions (3)
NVD, NVD, Wordfence
CWE (3)
CWE-264: Permissions, Privileges, and Access Controls
CWE-269: Improper Privilege Management
CWE-639: Authorization Bypass Through User-Controlled Key
CAPEC (-)
Risk
CVSS Score
7.2 High
SSVC
Track*
KEV
-
EPSS
0.1%
Affected Products (-)
Vendors (1)
oxilab
Products (1)
image_hover_effects_ultimate
Versions (1)
<= 9.7.1
Intel Resources (-)
Advisories (-)
-
Exploits (-)
-
Plugins (-)
-
References (2)
General (2)
patchstack, wordpress
Exploits & POcs (-)
Patches (-)
Advisories (-)
Summary
Descriptions

Auth. WordPress Options Change vulnerability in Image Hover Effects Ultimate plugin <= 9.7.1 on WordPress.

Vulnerabilidad de cambio de opciones de WordPress autenticada en el complemento Image Hover Effects Ultimate en WordPress en versiones &lt;= 9.7.1.

The Image Hover Effects Ultimate plugin for WordPress is vulnerable to Arbitrary Options Update in versions up to, and including, 9.7.1. This is due to a lack of validation on the settings supplied to the post_oxi_settings() function. This makes it possible for authenticated attackers, with administrative level permissions, to update arbitrary options on the WordPress site. This would only affect sites where the administrator has been restricted to not 'manage_options' or the administrator has allowed users with lower permissions to update the plugin's settings.

*Credits: Vulnerability discovered by Vlad Vector (Patchstack)
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
High
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Attack Vector
Network
Attack Complexity
Low
Authentication
Multiple
Confidentiality
Complete
Integrity
Complete
Availability
Complete
* Common Vulnerability Scoring System
SSVC
  • Decision:Track*
Exploitation
None
Automatable
No
Tech. Impact
Total
* Organization's Worst-case Scenario
Timeline
  • 2022-10-19 CVE Reserved
  • 2022-10-25 CVE Published
  • 2024-05-17 EPSS Updated
  • 2025-02-20 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-264: Permissions, Privileges, and Access Controls
  • CWE-269: Improper Privilege Management
  • CWE-639: Authorization Bypass Through User-Controlled Key
CAPEC
Threat Intelligence Resources (0)
Security Advisory details:

Select an advisory to view details here.

Select an exploit to view details here.

Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Oxilab
Search vendor "Oxilab"
Image Hover Effects Ultimate
Search vendor "Oxilab" for product "Image Hover Effects Ultimate"
<= 9.7.1
Search vendor "Oxilab" for product "Image Hover Effects Ultimate" and version " <= 9.7.1"
wordpress
Affected