AnyComment < 0.2.18 - Arbitrary HyperComments Import/Revert via CSRF
CVE-2022-0134
8.8HIGH
What is CVE-2022-0134?
The AnyComment WordPress plugin before 0.2.18 does not have CSRF checks in the Import and Revert HyperComments features, allowing attackers to make logged in admin perform such actions via a CSRF attack
Affected Version(s)
AnyComment 0.2.18