CVE-2022-2350
10.10.2022, 21:15
The Disable User Login WordPress plugin through 1.0.1 does not have authorisation and CSRF checks when updating its settings, allowing unauthenticated attackers to block (or unblock) users at will.
Vendor | Product | Version |
---|---|---|
brainvire | disable_user_login | 𝑥 ≤ 1.0.1 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration