PT-2022-24578 · WordPress · Wp Tools Increase Maximum Limits
Lana Codes
·
Published
2022-12-12
·
Updated
2022-12-14
·
CVE-2022-3881
CVSS v3.1
5.7
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
WP Tools Increase Maximum Limits, Repair, Server PHP Info, Javascript errors, File Permissions, Transients, Error Log WordPress plugin versions prior to 3.43
Description
The issue is related to improper authorization and CSRF in an AJAX action, allowing any authenticated users to install and activate arbitrary plugins from wordpress.org. This can be exploited by authenticated users, such as subscribers.
Recommendations
For versions prior to 3.43, update to version 3.43 or later to resolve the issue. As a temporary workaround, consider restricting access to the AJAX action to prevent unauthorized plugin installations.
Exploit
Fix
Incorrect Authorization
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Wp Tools Increase Maximum Limits