ZeroHour

CVE-2022-2388

PoC
CVSS 3.1
6.5 medium
EPSS
<1%p36
Published
()
Modified
Description

The WP Coder WordPress plugin before 2.5.3 does not have CSRF check in place when deleting code created by the plugin, which could allow attackers to make a logged in admin delete arbitrary ones via a CSRF attack

Vendors
wow-company
Products
wp coder
Ecosystems
WordPress
Weakness
CWE-352
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N

In the news

No ingested article mentions this CVE yet.