PT-2023-15326 · WordPress · Wp Customer Area

·

CVE-2022-4745

·

Publicado

2023-02-13

·

Atualizado

2025-04-03

CVSS v3.1

7.1

Alta

VetorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions WP Customer Area versions prior to 8.1.4
Description The issue concerns a lack of CSRF checks for certain actions, such as chmod, mkdir, and copy. This could allow attackers to make a logged-in admin perform these actions, resulting in the creation of arbitrary folders or the copying of files.
Recommendations For versions prior to 8.1.4, update to version 8.1.4 or later to resolve the issue. As a temporary workaround, consider restricting access to the affected plugin functionality until the update is applied.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2022-4745

Produtos afetados

Wp Customer Area