PT-2022-20426 · WordPress · Lbstopattack

Daniel Ruf

·

Published

2022-10-25

·

Updated

2022-11-29

·

CVE-2022-3097

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Plugin LBstopattack WordPress plugin versions prior to 1.1.3
Description The issue allows attackers to conduct CSRF attacks because the plugin does not use nonces when saving its settings. This could enable attackers to disable the plugin's protections.
Recommendations For versions prior to 1.1.3, update to version 1.1.3 or later to resolve the issue. As a temporary workaround, consider restricting access to the plugin's settings page to minimize the risk of exploitation.

Exploit

Fix

Related Identifiers

CVE-2022-3097

Affected Products

Lbstopattack