CVE-2022-43468
Last modified
CVE-2022-43468 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. External initialization of trusted variables or data stores vulnerability exists in WordPress Popular Posts 6.0.5 and earlier, therefore the vulnerable product accepts untrusted external inputs to update certain internal variables. As a result, the number of views for an article may be manipulated through a crafted input.. EPSS estimates a 0.85% chance of exploitation in the next 30 days.
Description
External initialization of trusted variables or data stores vulnerability exists in WordPress Popular Posts 6.0.5 and earlier, therefore the vulnerable product accepts untrusted external inputs to update certain internal variables. As a result, the number of views for an article may be manipulated through a crafted input.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Wordpress Popular Posts Project | Wordpress Popular Posts | <= 6.0.5 |
References
- https://github.com/cabrerahector/wordpress-popular-posts/Third Party Advisory
- https://jvn.jp/en/jp/JVN13927745/index.htmlThird Party Advisory
- https://github.com/cabrerahector/wordpress-popular-posts/Third Party Advisory
- https://jvn.jp/en/jp/JVN13927745/index.htmlThird Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-43468?
How severe is CVE-2022-43468?
How do I fix CVE-2022-43468?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2022
- CVE-2022-43462Auth. SQL Injection (SQLi) vulnerability in Adeel Ahmed's IP…7.2
- CVE-2022-43463Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerabili…4.8
- CVE-2022-43464Hidden functionality vulnerability in UDR-JA1604/UDR-JA1608/…8.8
- CVE-2022-43465Improper authorization in the Intel(R) SCS software all vers…5.5
- CVE-2022-43466OS command injection vulnerability in Buffalo network device…6.8
- CVE-2022-43467An out-of-bounds write vulnerability exists in the PQS forma…7.8
- CVE-2022-43469Cross-Site Request Forgery (CSRF) vulnerability in Orchestra…8.8
- CVE-2022-4347A vulnerability was found in xiandafu beetl-bbs. It has been…5.4
- CVE-2022-43470Cross-site request forgery (CSRF) vulnerability in +F FS040U…7.3
- CVE-2022-43472Missing Authorization vulnerability in StylemixThemes eRoom …4.3
- CVE-2022-43473A blind XML External Entity (XXE) vulnerability exists in th…5.4
- CVE-2022-43474Uncontrolled search path for the DSP Builder software instal…7.8
Are you affected by CVE-2022-43468?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
