ZeroHour

CVE-2022-1570

PoC
CVSS 3.1
6.5 medium
EPSS
<1%p36
Published
()
Modified
Description

The Files Download Delay WordPress plugin before 1.0.7 does not have authorisation and CSRF checks when reseting its settings, which could allow any authenticated users, such as subscriber to perform such action.

Vendors
files download delay project
Products
files download delay
Ecosystems
WordPress
Weakness
CWE-352, CWE-862
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

In the news

No ingested article mentions this CVE yet.