PT-2022-19890 · WordPress · Ldap Wp Login / Active Directory Integration
Lana Codes
·
Published
2022-09-26
·
Updated
2023-07-20
·
CVE-2022-2987
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Ldap WP Login / Active Directory Integration WordPress plugin versions prior to 3.0.2
Description
The issue concerns a lack of authorization and CSRF checks when updating settings in the Ldap WP Login / Active Directory Integration WordPress plugin. This allows unauthenticated attackers to update the settings, which are hooked to the init action. Attackers could set their own LDAP server to be used for authenticating users, thereby bypassing the current authentication.
Recommendations
For versions prior to 3.0.2, update to version 3.0.2 or later to resolve the issue. As a temporary workaround, consider restricting access to the settings update functionality to prevent unauthenticated updates until a patch is applied.
Exploit
Fix
Missing Authorization
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ldap Wp Login / Active Directory Integration