CVE-2022-43468 Vulnerability Details

  /     /     /  

CVE-2022-43468 Metadata Quick Info

CVE Published: 07/12/2022 | CVE Updated: 03/08/2024 | CVE Year: 2022
Source: jpcert | Vendor: Hector Cabrera | Product: WordPress Popular Posts
Status : PUBLISHED

CVE-2022-43468 Description

External initialization of trusted variables or data stores vulnerability exists in WordPress Popular Posts 6.0.5 and earlier, therefore the vulnerable product accepts untrusted external inputs to update certain internal variables. As a result, the number of views for an article may be manipulated through a crafted input.

Metrics

CVSS Version: 3.1 | Base Score: n/a
Vector: n/a

l➤ Exploitability Metrics:
    Attack Vector (AV)*
    Attack Complexity (AC)*
    Privileges Required (PR)*
    User Interaction (UI)*
    Scope (S)*

l➤ Impact Metrics:
    Confidentiality Impact (C)*
    Integrity Impact (I)*
    Availability Impact (A)*

Weakness Enumeration (CWE)

CWE-ID:
CWE Name: External Initialization of Trusted Variables or Data Stores
Source: Hector Cabrera

Common Attack Pattern Enumeration and Classification (CAPEC)

CAPEC-ID:
CAPEC Description:


Source: NVD (National Vulnerability Database).