CVE-2022-3881
Last modified
CVE-2022-3881 is a medium-severity vulnerability rated 5.7/10 on the CVSS scale. The WP Tools Increase Maximum Limits, Repair, Server PHP Info, Javascript errors, File Permissions, Transients, Error Log WordPress plugin before 3.43 does not have proper authorisation and CSRF in an AJAX action, allowing any authenticated users, such as subscriber to call it and install and activate arbitrary plugins from wordpress.org. EPSS estimates a 0.44% chance of exploitation in the next 30 days.
Description
The WP Tools Increase Maximum Limits, Repair, Server PHP Info, Javascript errors, File Permissions, Transients, Error Log WordPress plugin before 3.43 does not have proper authorisation and CSRF in an AJAX action, allowing any authenticated users, such as subscriber to call it and install and activate arbitrary plugins from wordpress.org
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Wptools Project | Wptools | < 3.43 |
References
- https://wpscan.com/vulnerability/c2a9cf01-051a-429a-82ca-280885114b5aExploit, Third Party Advisory
- https://wpscan.com/vulnerability/c2a9cf01-051a-429a-82ca-280885114b5aExploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-3881?
How severe is CVE-2022-3881?
How do I fix CVE-2022-3881?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2022
- CVE-2022-38796A Host Header Injection vulnerability in Feehi CMS 2.1.1 may…6.1
- CVE-2022-3880The Disable Json API, Login Lockdown, XMLRPC, Pingback, Stop…6.5
- CVE-2022-38801In Zkteco BioTime < 8.5.3 Build:20200816.447, an employee ca…5.4
- CVE-2022-38802Zkteco BioTime < 8.5.3 Build:20200816.447 is vulnerable to I…6.2
- CVE-2022-38803Zkteco BioTime < 8.5.3 Build:20200816.447 is vulnerable to I…6.8
- CVE-2022-38808ywoa v6.1 is vulnerable to SQL Injection via backend/oa/visu…8.8
- CVE-2022-38812AeroCMS 0.1.1 is vulnerable to SQL Injection via the author …6.5
- CVE-2022-38813PHPGurukul Blood Donor Management System 1.0 does not proper…8.1
- CVE-2022-38814A stored cross-site scripting (XSS) vulnerability in the aut…5.4
- CVE-2022-38817Dapr Dashboard v0.1.0 through v0.10.0 is vulnerable to Incor…7.5
- CVE-2022-3882The Memory Usage, Memory Limit, PHP and Server Memory Health…6.5
- CVE-2022-38823In TOTOLINK T6 V4.1.5cu.709_B20210518, there is a hard coded…9.8
Are you affected by CVE-2022-3881?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
