CVE-2022-1956
Summary
| CVE | CVE-2022-1956 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-07-11 13:15:00 UTC |
| Updated | 2022-11-03 17:31:00 UTC |
| Description | The Shortcut Macros WordPress plugin through 1.3 does not have authorisation and CSRF checks in place when updating its settings, which could allow any authenticated users, such as subscriber, to update them. |
Risk And Classification
Problem Types: CWE-352
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Shortcut Macros Project | Shortcut Macros | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Shortcut Macros <= 1.3 - Subscriber+ Arbitrary Settings Update WordPress Security Vulnerability | MISC | wpscan.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
LEGACY: Daniel Ruf
There are currently no legacy QID mappings associated with this CVE.