ZeroHour

CVE-2022-0134

PoC
CVSS 3.1
8.8 high
EPSS
<1%p49
Published
()
Modified
Description

The AnyComment WordPress plugin before 0.2.18 does not have CSRF checks in the Import and Revert HyperComments features, allowing attackers to make logged in admin perform such actions via a CSRF attack

Vendors
bologer
Products
anycomment
Ecosystems
WordPress
Weakness
CWE-352
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.