ZeroHour

CVE-2022-1589

PoC
CVSS 3.1
7.5 high
EPSS
<1%p47
Published
()
Modified
Description

The Change wp-admin login WordPress plugin before 1.1.0 does not properly check for authorisation and is also missing CSRF check when updating its settings, which could allow unauthenticated users to change the settings. The attacked could also be performed via a CSRF vector

Vendors
wpexperts
Products
all in one login
Ecosystems
WordPress
Weakness
CWE-352, CWE-863
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

In the news

No ingested article mentions this CVE yet.