Auth. (subscriber+) Broken Access Control vulnerability in David Cole Simple SEO plugin <= 1.8.12 on WordPress allows attackers to create or delete sitemap.
References
Link | Resource |
---|---|
https://wordpress.org/plugins/cds-simple-seo/#developers | Product Release Notes Third Party Advisory |
https://patchstack.com/database/vulnerability/cds-simple-seo/wordpress-simple-seo-plugin-1-8-12-authenticated-sitemap-deletion-creation-vulnerability?_s_id=cve | Third Party Advisory |
Configurations
Information
Published : 2022-11-03 13:15
Updated : 2022-11-04 07:10
NVD link : CVE-2022-36404
Mitre link : CVE-2022-36404
JSON object : View
CWE
CWE-863
Incorrect Authorization
Products Affected
coleds
- simple_seo