WordPress WIP Custom Login Plugin <= 1.2.7 is vulnerable to Broken Access Control
CVE-2022-42884
What is CVE-2022-42884?
The missing authorization vulnerability in ThemeinProgress's WIP Custom Login plugin allows unauthorized access, potentially leading to unauthorized actions by unauthenticated users. This vulnerability affects all versions of the WIP Custom Login plugin up to and including version 1.2.7, making WordPress installations susceptible to exploitation. Proper access controls are crucial to ensure that only authorized users can perform specific actions within the application, and this oversight could have significant security implications for affected websites.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
WIP Custom Login <= 1.2.7
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved