ZeroHour

CVE-2022-1663

PoC
CVSS 3.1
6.5 medium
EPSS
<1%p50
Published
()
Modified
Description

The Stop Spam Comments WordPress plugin through 0.2.1.2 does not properly generate the Javascript access token for preventing abuse of comment section, allowing threat authors to easily collect the value and add it to the request.

Vendors
stop spam comments project
Products
stop spam comments
Ecosystems
WordPress
Weakness
CWE-200
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.