PT-2022-22403 · WordPress · Wp Libre Form

Christian Nikkanen

·

Published

2022-09-06

·

Updated

2022-09-09

·

CVE-2022-34867

CVSS v3.1

7.3

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions WP Libre Form plugin versions 2.0.0 through 2.0.8
Description The issue allows attackers to disclose sensitive information and perform unauthorized actions, such as listing and deleting submissions, without proper authentication.
Recommendations For WP Libre Form plugin versions 2.0.0 through 2.0.8, update to a version higher than 2.0.8 to resolve the issue.

Fix

Information Disclosure

Exposure of Resource to Wrong Sphere

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-34867
GHSA-29QV-HHG4-6X96

Affected Products

Wp Libre Form