CVE-2022-43468
WordPress Popular Posts <= 6.0.5 - Unauthenticated Views Changes
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
External initialization of trusted variables or data stores vulnerability exists in WordPress Popular Posts 6.0.5 and earlier, therefore the vulnerable product accepts untrusted external inputs to update certain internal variables. As a result, the number of views for an article may be manipulated through a crafted input.
Vulnerabilidad de inicialización externa de variables confiables o almacenes de datos existe en WordPress Popular Posts 6.0.5 y versiones anteriores, por lo tanto, el producto vulnerable acepta entradas externas que no son confiables para actualizar ciertas variables internas. Como resultado, el número de vistas de un artículo puede manipularse mediante una entrada manipulada.
The WordPress Popular Posts plugin for WordPress is vulnerable to Unauthenticated Views Changes in versions up to, and including, 6.0.5. This is due to a lack of user input validation on a REST endpoint that results in unprotected behavior in the 'update_views_count' function. This makes it possible for unauthenticated attackers to manipulate and potentially change the views count endpoint.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2022-11-16 CVE Reserved
- 2022-11-18 CVE Published
- 2024-06-29 EPSS Updated
- 2024-08-03 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-284: Improper Access Control
- CWE-665: Improper Initialization
CAPEC
References (3)
URL | Tag | Source |
---|---|---|
https://github.com/cabrerahector/wordpress-popular-posts | Third Party Advisory | |
https://jvn.jp/en/jp/JVN13927745/index.html | Third Party Advisory | |
https://wordpress.org/plugins/wordpress-popular-posts | Product |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Wordpress Popular Posts Project Search vendor "Wordpress Popular Posts Project" | Wordpress Popular Posts Search vendor "Wordpress Popular Posts Project" for product "Wordpress Popular Posts" | <= 6.0.5 Search vendor "Wordpress Popular Posts Project" for product "Wordpress Popular Posts" and version " <= 6.0.5" | wordpress |
Affected
|