CVE-2022-4872 Vulnerability Details
/
/
/
CVE-2022-4872 Metadata Quick Info
CVE Published: 30/01/2023 |
CVE Updated: 03/08/2024 |
CVE Year: 2022
Source: WPScan |
Vendor: Unknown |
Product: Chained Products
Status : PUBLISHED
CVE-2022-4872 Description
The Chained Products WordPress plugin before 2.12.0 does not have authorisation and CSRF checks, as well as does not ensure that the option to be updated belong to the plugin, allowing unauthenticated attackers to set arbitrary options to \'no\'
Metrics
CVSS Version: 3.1 |
Base Score: n/a
Vector: n/a
l➤ Exploitability Metrics:
Attack Vector (AV)*
Attack Complexity (AC)*
Privileges Required (PR)*
User Interaction (UI)*
Scope (S)*
l➤ Impact Metrics:
Confidentiality Impact (C)*
Integrity Impact (I)*
Availability Impact (A)*
Weakness Enumeration (CWE)
CWE-ID:
CWE Name: CWE-862 Missing Authorization
Source: Unknown
Common Attack Pattern Enumeration and Classification (CAPEC)
CAPEC-ID:
CAPEC Description:
Source: NVD (National Vulnerability Database).