PT-2022-22782 · WordPress · Webmaster Tools Verification
Daniel Ruf
·
Published
2022-11-14
·
Updated
2025-04-30
·
CVE-2022-3538
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Webmaster Tools Verification WordPress plugin versions through 1.2
Description
The issue concerns a lack of authorisation and CSRF checks when disabling plugins, allowing unauthenticated users to disable arbitrary plugins.
Recommendations
For Webmaster Tools Verification WordPress plugin versions through 1.2, consider disabling the plugin disabling functionality until a patch is available. Restrict access to the plugin management interface to minimize the risk of exploitation.
Exploit
Fix
Missing Authorization
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Webmaster Tools Verification