PT-2022-13666 · WordPress · Autolink
Vaibhav Nitin Gaikwad
·
Published
2022-04-18
·
Updated
2022-04-27
·
CVE-2022-1112
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Autolinks WordPress plugin version 1.0.1
Description
The issue is related to the lack of a CSRF check when updating settings and the failure to sanitize and escape input, which could allow attackers to perform Stored Cross-Site scripting against a logged-in admin via a CSRF attack.
Recommendations
For Autolinks WordPress plugin version 1.0.1, consider updating to a newer version that includes a CSRF check and proper input sanitization and escaping to prevent Stored Cross-Site scripting attacks. As a temporary workaround, restrict access to the plugin's settings update functionality to minimize the risk of exploitation.
Exploit
Fix
XSS
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Autolink