CVE-2022-1599
11.07.2022, 13:15
The Admin Management Xtended WordPress plugin before 2.4.5 does not have CSRF checks in some of its AJAX actions, allowing attackers to make a logged users with the right capabilities to call them. This can lead to changes in post status (draft, published), slug, post date, comment status (enabled, disabled) and more.
Vendor | Product | Version |
---|---|---|
admin_management_xtended_project | admin_management_xtended | 𝑥 < 2.4.5 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration