CVE-2022-1913
Last modified
CVE-2022-1913 is a medium-severity vulnerability rated 4.3/10 on the CVSS scale. The Add Post URL WordPress plugin through 2.1.0 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack and lead to Stored Cross-Site Scripting due to the lack of sanitisation and escaping. EPSS estimates a 0.41% chance of exploitation in the next 30 days.
Description
The Add Post URL WordPress plugin through 2.1.0 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack and lead to Stored Cross-Site Scripting due to the lack of sanitisation and escaping
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Add Post Url Project | Add Post Url | <= 2.1.0 |
References
- https://wpscan.com/vulnerability/2cafef43-e64a-4897-8c41-f0ed473d7eadExploit, Third Party Advisory
- https://wpscan.com/vulnerability/2cafef43-e64a-4897-8c41-f0ed473d7eadExploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-1913?
How severe is CVE-2022-1913?
How do I fix CVE-2022-1913?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2022
- CVE-2022-1907Buffer Over-read in GitHub repository bfabiszewski/libmobi p…8.1
- CVE-2022-1908Buffer Over-read in GitHub repository bfabiszewski/libmobi p…8.1
- CVE-2022-1909Cross-site Scripting (XSS) - Stored in GitHub repository cau…5.4
- CVE-2022-1910The Shortcodes and extra features for Phlox WordPress plugin…6.1
- CVE-2022-1911Error in parser function in M-Files Server versions before 2…5.3
- CVE-2022-1912The Button Widget Smartsoft plugin for WordPress is vulnerab…8.8
- CVE-2022-1914The Clean-Contact WordPress plugin through 1.6 does not have…4.3
- CVE-2022-1915The WP Zillow Review Slider WordPress plugin before 2.4 does…4.8
- CVE-2022-1916The Active Products Tables for WooCommerce. Professional pro…6.1
- CVE-2022-1918The ToolBar to Share plugin for WordPress is vulnerable to C…8.8
- CVE-2022-1919Use after free in Codecs in Google Chrome prior to 101.0.495…8.8
- CVE-2022-1920Integer overflow in matroskademux element in gst_matroska_de…7.8
Are you affected by CVE-2022-1913?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
