CVE-2022-4265
Last modified
CVE-2022-4265 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. The Replyable WordPress plugin before 2.2.10 does not validate the class name submitted by the request when instantiating an object in the prompt_dismiss_notice action and also lacks CSRF check in the related action. This could allow any authenticated users, such as subscriber to perform Object Injection attacks. EPSS estimates a 0.51% chance of exploitation in the next 30 days.
Description
The Replyable WordPress plugin before 2.2.10 does not validate the class name submitted by the request when instantiating an object in the prompt_dismiss_notice action and also lacks CSRF check in the related action. This could allow any authenticated users, such as subscriber to perform Object Injection attacks. The attack could also be done via a CSRF vector against any authenticated user
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Gopostmatic | Replyable | < 2.2.10 |
References
- https://wpscan.com/vulnerability/095cba08-7edd-41fb-9776-da151c0885ddExploit, Third Party Advisory
- https://wpscan.com/vulnerability/095cba08-7edd-41fb-9776-da151c0885ddExploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-4265?
How severe is CVE-2022-4265?
How do I fix CVE-2022-4265?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2022
- CVE-2022-4258In multiple versions of HIMA PC based Software an unquoted W…7.8
- CVE-2022-4259Due to improper input validation in the Alerts controller, a…8.8
- CVE-2022-4260The WP-Ban WordPress plugin before 1.69.1 does not sanitise …4.8
- CVE-2022-4261Rapid7 Nexpose and InsightVM versions prior to 6.6.172 faile…6.5
- CVE-2022-4262Type confusion in V8 in Google Chrome prior to 108.0.5359.94…8.8
- CVE-2022-4264Incorrect Privilege Assignment in M-Files Web (Classic) in M…4.3
- CVE-2022-4266The Bulk Delete Users by Email WordPress plugin through 1.2 …6.5
- CVE-2022-4267The Bulk Delete Users by Email WordPress plugin through 1.2 …6.1
- CVE-2022-4268The Plugin Logic WordPress plugin before 1.0.8 does not sani…7.2
- CVE-2022-4269A flaw was found in the Linux kernel Traffic Control (TC) su…5.5
- CVE-2022-42698Unauth. Arbitrary File Upload vulnerability in WordPress Api…9.8
- CVE-2022-42699Auth. Remote Code Execution vulnerability in Easy WP SMTP pl…8.8
Are you affected by CVE-2022-4265?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
