CVE-2022-4553
Last modified
CVE-2022-4553 is a medium-severity vulnerability rated 4.3/10 on the CVSS scale. The FL3R FeelBox WordPress plugin through 8.1 does not have CSRF check when updating reseting moods which could allow attackers to make logged in admins perform such action via a CSRF attack and delete the lydl_posts & lydl_poststimestamp DB tables. EPSS estimates a 0.27% chance of exploitation in the next 30 days.
Description
The FL3R FeelBox WordPress plugin through 8.1 does not have CSRF check when updating reseting moods which could allow attackers to make logged in admins perform such action via a CSRF attack and delete the lydl_posts & lydl_poststimestamp DB tables
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Armandofiore | Fl3r Feelbox | <= 8.1 |
References
- https://wpscan.com/vulnerability/483ed482-a1d1-44f6-8b99-56e653d3e45fExploit, Third Party Advisory
- https://wpscan.com/vulnerability/483ed482-a1d1-44f6-8b99-56e653d3e45fExploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2022-4553?
How severe is CVE-2022-4553?
How do I fix CVE-2022-4553?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2022
- CVE-2022-45523Tenda W30E V1.0.1.25(633) was discovered to contain a stack …7.5
- CVE-2022-45524Tenda W30E V1.0.1.25(633) was discovered to contain a stack …7.5
- CVE-2022-45525Tenda W30E V1.0.1.25(633) was discovered to contain a stack …7.5
- CVE-2022-45526SQL Injection vulnerability in Future-Depth Institutional Ma…9.8
- CVE-2022-45527File upload vulnerability in Future-Depth Institutional Mana…9.8
- CVE-2022-45529AeroCMS v0.0.1 was discovered to contain a SQL Injection vul…4.9
- CVE-2022-45535AeroCMS v0.0.1 was discovered to contain a SQL Injection vul…4.9
- CVE-2022-45536AeroCMS v0.0.1 was discovered to contain a SQL Injection vul…4.9
- CVE-2022-45537EyouCMS <= 1.6.0 was discovered a reflected-XSS in the artic…6.1
- CVE-2022-45538EyouCMS <= 1.6.0 was discovered a reflected-XSS in the artic…6.1
- CVE-2022-45539EyouCMS <= 1.6.0 was discovered a reflected-XSS in FileManag…6.1
- CVE-2022-4554B2B Customer Ordering System developed by ID Software Projec…5.4
Are you affected by CVE-2022-4553?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
