PT-2022-19588 · WordPress · Subscribe To Comments Reloaded
Re-Alter
+1
·
Published
2022-04-29
·
Updated
2022-05-10
·
CVE-2022-29414
CVSS v2.0
5.8
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Subscribe To Comments Reloaded plugin versions <= 211130
Description
The issue affects the Subscribe To Comments Reloaded plugin on WordPress, allowing attackers to perform various actions due to multiple Cross-Site Request Forgery (CSRF) vulnerabilities. These actions include cleaning up the Log archive, downloading system info files, modifying plugin settings, generating new keys, resetting options, and changing notification settings, among others.
Recommendations
For Subscribe To Comments Reloaded plugin versions <= 211130, consider temporarily disabling the plugin until a patch is available to prevent exploitation of the CSRF vulnerabilities. Restrict access to the management and settings pages of the plugin to minimize the risk of unauthorized changes. Avoid using the plugin's functionality for sensitive operations until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Subscribe To Comments Reloaded