Lucene search

K
cvelistWPScanCVELIST:CVE-2022-3880
HistoryDec 12, 2022 - 5:54 p.m.

CVE-2022-3880 AntiHacker < 4.20 - Subscriber+ Arbitrary Plugin Installation

2022-12-1217:54:54
WPScan
www.cve.org
3
cve-2022-3880
antihacker
subscriber
plugin installation
authorization
csrf
ajax
wordpress

EPSS

0.001

Percentile

37.7%

The Disable Json API, Login Lockdown, XMLRPC, Pingback, Stop User Enumeration Anti Hacker Scan WordPress plugin before 4.20 does not have proper authorisation and CSRF in an AJAX action, allowing any authenticated users, such as subscriber to call it and install and activate arbitrary plugins from wordpress.org

CNA Affected

[
  {
    "vendor": "Unknown",
    "product": "Disable Json API, Login Lockdown, XMLRPC, Pingback, Stop User Enumeration Anti Hacker Scan",
    "collectionURL": "https://wordpress.org/plugins",
    "versions": [
      {
        "status": "affected",
        "versionType": "custom",
        "version": "0",
        "lessThan": "4.20"
      }
    ],
    "defaultStatus": "unaffected"
  }
]

EPSS

0.001

Percentile

37.7%

Related for CVELIST:CVE-2022-3880