PT-2022-16032 · WordPress · Disable User Login
Rafshanzani Suhada
·
Published
2022-10-10
·
Updated
2023-07-14
·
CVE-2022-2350
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L |
Name of the Vulnerable Software and Affected Versions
Disable User Login WordPress plugin versions 1.0.0 through 1.0.1
Description
The issue concerns a lack of authorization and CSRF checks when updating settings in the Disable User Login WordPress plugin. This allows unauthenticated attackers to block or unblock users at will.
Recommendations
For Disable User Login WordPress plugin versions 1.0.0 through 1.0.1, consider disabling the plugin until a patch is available to add the necessary authorization and CSRF checks. Restrict access to the plugin's settings to minimize the risk of exploitation.
Exploit
Fix
Missing Authorization
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Disable User Login