PT-2022-13986 · WordPress · Change Wp-Admin Login Wordpress Plugin
Daniel Ruf
·
Published
2022-05-30
·
Updated
2023-07-04
·
CVE-2022-1589
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
The Change wp-admin login WordPress plugin versions prior to 1.1.0
Description
The issue arises from the plugin's failure to properly check for authorization and its lack of CSRF check when updating settings. This could allow unauthenticated users to change the settings, and the attack could also be performed via a CSRF vector.
Recommendations
For versions prior to 1.1.0, update to version 1.1.0 or later to resolve the issue. As a temporary workaround, consider restricting access to the plugin's settings page to minimize the risk of exploitation. Avoid using the plugin until the issue is resolved.
Exploit
Fix
Incorrect Authorization
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Change Wp-Admin Login Wordpress Plugin