Cross-Site Request Forgery in Corner Ad Plugin for WordPress
CVE-2022-3427

8.8HIGH

Key Information:

Vendor
Wordpress
Status
Vendor
CVE Published:
15 December 2022

Summary

The Corner Ad plugin for WordPress is susceptible to a Cross-Site Request Forgery vulnerability due to insufficient nonce validation in the corner_ad_settings_page function. This weakness allows attackers to exploit the plugin by tricking site administrators into executing unintended actions, such as deleting advertisements, without their consent. The issue exists in versions up to and including 1.0.56, emphasizing the need for immediate attention from users and administrators to apply updates or implement necessary mitigations.

Affected Version(s)

Corner Ad * <= 1.0.56

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Marco Wotschka
.