PT-2022-14145 · WordPress · Cross-Linker

Daniel Ruf

·

Published

2022-06-20

·

Updated

2022-06-28

·

CVE-2022-1826

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Cross-Linker WordPress plugin versions through 3.0.1.9
Description The issue concerns the lack of a CSRF check when creating Cross-Links, potentially allowing attackers to perform actions on behalf of a logged-in admin via a CSRF attack.
Recommendations For Cross-Linker WordPress plugin versions through 3.0.1.9, consider disabling the Cross-Link creation feature until a patch is available to prevent potential CSRF attacks.

Exploit

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-1826

Affected Products

Cross-Linker