Admin Management Xtended < 2.4.5 - Post Visibility/Date/Comment Status Update via CSRF
CVE-2022-1599

6.5MEDIUM

Key Information:

Vendor
Wordpress
Vendor
CVE Published:
11 July 2022

Summary

The Admin Management Xtended WordPress plugin before 2.4.5 does not have CSRF checks in some of its AJAX actions, allowing attackers to make a logged users with the right capabilities to call them. This can lead to changes in post status (draft, published), slug, post date, comment status (enabled, disabled) and more.

Affected Version(s)

Admin Management Xtended 2.4.5

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Daniel Ruf
.