PT-2022-20029 · WordPress · Simple Bitcoin Faucets

Lana Codes

·

Published

2022-09-26

·

Updated

2022-12-09

·

CVE-2022-3024

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions The Simple Bitcoin Faucets WordPress plugin versions 1.7.0 and earlier
Description The issue is related to the lack of authorisation and CSRF in an AJAX action, allowing any authenticated users to call it and add/delete/edit Bonds. This could also lead to Stored Cross-Site Scripting issues due to the lack of sanitisation and escaping.
Recommendations For versions 1.7.0 and earlier, update to a version that includes proper authorisation and CSRF protection in AJAX actions, and ensure that user input is properly sanitised and escaped to prevent Stored Cross-Site Scripting issues. As a temporary workaround, consider restricting access to the AJAX action to prevent exploitation until a patch is available.

Exploit

Fix

Incorrect Authorization

CSRF

Weakness Enumeration

Related Identifiers

CVE-2022-3024

Affected Products

Simple Bitcoin Faucets