ZeroHour

CVE-2022-4745

PoC
CVSS 3.1
7.1 high
EPSS
<1%p20
Published
()
Modified
Description

The WP Customer Area WordPress plugin before 8.1.4 does not have CSRF checks when performing some actions such as chmod, mkdir and copy, which could allow attackers to make a logged-in admin perform them and create arbitrary folders, copy file for example.

Vendors
wp-customerarea
Products
wp customer area
Ecosystems
WordPress
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N

In the news

No ingested article mentions this CVE yet.