Cross-Site Request Forgery in Corner Ad Plugin for WordPress
CVE-2022-3427
What is CVE-2022-3427?
The Corner Ad plugin for WordPress is susceptible to a Cross-Site Request Forgery vulnerability due to insufficient nonce validation in the corner_ad_settings_page function. This weakness allows attackers to exploit the plugin by tricking site administrators into executing unintended actions, such as deleting advertisements, without their consent. The issue exists in versions up to and including 1.0.56, emphasizing the need for immediate attention from users and administrators to apply updates or implement necessary mitigations.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Corner Ad * <= 1.0.56
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved