PT-2022-13710 · WordPress · Content Mask

Ptsfence

·

Published

2022-05-30

·

Updated

2023-07-04

·

CVE-2022-1203

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Content Mask WordPress plugin versions prior to 1.8.4.1
Description The issue concerns a lack of authorization and CSRF checks in various AJAX actions within the plugin, as well as a failure to validate options being updated to ensure they belong to the plugin. This allows any authenticated user, such as a subscriber, to modify arbitrary blog options.
Recommendations For Content Mask WordPress plugin versions prior to 1.8.4.1, update to version 1.8.4.1 or later to resolve the issue. As a temporary workaround, consider restricting access to AJAX actions and validating user permissions to minimize the risk of exploitation.

Exploit

Fix

Missing Authorization

CSRF

Weakness Enumeration

Related Identifiers

CVE-2022-1203

Affected Products

Content Mask