WordPress WIP Custom Login Plugin <= 1.2.7 is vulnerable to Broken Access Control
CVE-2022-42884

5.4MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
17 January 2024

What is CVE-2022-42884?

The missing authorization vulnerability in ThemeinProgress's WIP Custom Login plugin allows unauthorized access, potentially leading to unauthorized actions by unauthenticated users. This vulnerability affects all versions of the WIP Custom Login plugin up to and including version 1.2.7, making WordPress installations susceptible to exploitation. Proper access controls are crucial to ensure that only authorized users can perform specific actions within the application, and this oversight could have significant security implications for affected websites.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

WIP Custom Login <= 1.2.7

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

István Márton (Patchstack Alliance)
.