ZeroHour

CVE-2022-3082

PoC
CVSS 3.1
6.5 medium
EPSS
<1%p37
Published
()
Modified
Description

The miniOrange Discord Integration WordPress plugin before 2.1.6 does not have authorisation and CSRF in some of its AJAX actions, allowing any logged in users, such as subscriber to call them, and disable the app for example

Vendors
miniorange
Products
discord integration
Ecosystems
WordPress
Weakness
CWE-352, CWE-862
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.