CVE-2022-2350
PoC —CVSS 3.1
5.3 medium
EPSS
<1%p38
Published
()
Modified
Description
The Disable User Login WordPress plugin through 1.0.1 does not have authorisation and CSRF checks when updating its settings, allowing unauthenticated attackers to block (or unblock) users at will.
- Vendors
- brainvire
- Products
- disable user login
- Ecosystems
- WordPress
- Weakness
- CWE-352, CWE-862
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
In the news0 stories
No ingested article mentions this CVE yet.