PT-2022-24578 · WordPress · Wp Tools Increase Maximum Limits

Lana Codes

·

Published

2022-12-12

·

Updated

2022-12-14

·

CVE-2022-3881

CVSS v3.1

5.7

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions WP Tools Increase Maximum Limits, Repair, Server PHP Info, Javascript errors, File Permissions, Transients, Error Log WordPress plugin versions prior to 3.43
Description The issue is related to improper authorization and CSRF in an AJAX action, allowing any authenticated users to install and activate arbitrary plugins from wordpress.org. This can be exploited by authenticated users, such as subscribers.
Recommendations For versions prior to 3.43, update to version 3.43 or later to resolve the issue. As a temporary workaround, consider restricting access to the AJAX action to prevent unauthorized plugin installations.

Exploit

Fix

Incorrect Authorization

CSRF

Weakness Enumeration

Related Identifiers

CVE-2022-3881

Affected Products

Wp Tools Increase Maximum Limits