CVE-2022-3538

The Webmaster Tools Verification WordPress plugin through 1.2 does not have authorisation and CSRF checks when disabling plugins, allowing unauthenticated users to disable arbitrary plugins
References
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

cpe:2.3:a:webmaster_tools_verification_project:webmaster_tools_verification:*:*:*:*:*:wordpress:*:*

Information

Published : 2022-11-14 07:15

Updated : 2022-11-16 11:07


NVD link : CVE-2022-3538

Mitre link : CVE-2022-3538


JSON object : View

CWE
CWE-352

Cross-Site Request Forgery (CSRF)

CWE-862

Missing Authorization

Advertisement

dedicated server usa

Products Affected

webmaster_tools_verification_project

  • webmaster_tools_verification