PT-2022-14108 · WordPress · Auto Delete Posts

Daniel Ruf

·

Published

2022-06-13

·

Updated

2022-06-21

·

CVE-2022-1779

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions Auto Delete Posts WordPress plugin versions 1.3.0 and earlier
Description The issue is related to the lack of a CSRF check when updating the plugin's settings. This could allow attackers to make a logged-in admin change the settings via a CSRF attack, resulting in the deletion of specific posts, categories, and attachments at once.
Recommendations For versions 1.3.0 and earlier, update to a version that includes a CSRF check to prevent unauthorized changes to the plugin's settings. As a temporary workaround, consider restricting access to the plugin's settings page to minimize the risk of exploitation.

Exploit

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-1779

Affected Products

Auto Delete Posts