External initialization of trusted variables or data stores vulnerability exists in WordPress Popular Posts 6.0.5 and earlier, therefore the vulnerable product accepts untrusted external inputs to update certain internal variables. As a result, the number of views for an article may be manipulated through a crafted input.
References
Link | Resource |
---|---|
https://github.com/cabrerahector/wordpress-popular-posts/ | Third Party Advisory |
https://jvn.jp/en/jp/JVN13927745/index.html | Third Party Advisory |
https://wordpress.org/plugins/wordpress-popular-posts/ | Product |
Configurations
Configuration 1 (hide)
|
Information
Published : 2022-12-06 20:15
Updated : 2022-12-08 16:28
NVD link : CVE-2022-43468
Mitre link : CVE-2022-43468
JSON object : View
CWE
CWE-665
Improper Initialization
Products Affected
wordpress_popular_posts_project
- wordpress_popular_posts