PT-2022-14110 · WordPress · Posttabs
Daniel Ruf
·
Published
2022-06-13
·
Updated
2022-06-21
·
CVE-2022-1781
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
postTabs WordPress plugin versions 2.10.6 and earlier
Description
The issue is related to the lack of a CSRF check when updating settings in the postTabs WordPress plugin, which could allow attackers to make a logged-in admin change them via a CSRF attack. This also leads to Stored Cross-Site Scripting due to the lack of sanitization and escaping.
Recommendations
For postTabs WordPress plugin versions 2.10.6 and earlier, update to a version that includes a CSRF check and proper sanitization and escaping to prevent these issues.
Exploit
Fix
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Posttabs