CVE-2022-40671
Published on: Not Yet Published
Last Modified on: 09/26/2022 04:28:00 PM UTC
Certain versions of Rate My Post - Wp Rating System from Blazzdev contain the following vulnerability:
Cross-Site Request Forgery (CSRF) vulnerability in Rate my Post – WP Rating System plugin <= 3.3.4 at WordPress.
- CVE-2022-40671 has been assigned by
audit@patchstack.com to track the vulnerability - currently rated as MEDIUM severity.
- Affected Vendor/Software:
Blaz K. - Rate my Post – WP Rating System (WordPress plugin) version <= 3.3.4
CVSS3 Score: 4.3 - MEDIUM
Attack Vector ⓘ |
Attack Complexity |
Privileges Required |
User Interaction |
---|---|---|---|
NETWORK | LOW | NONE | REQUIRED |
Scope | Confidentiality Impact |
Integrity Impact |
Availability Impact |
UNCHANGED | NONE | LOW | NONE |
CVE References
Description | Tags ⓘ | Link |
---|---|---|
Rate my Post – WP Rating System – WordPress plugin | WordPress.org | wordpress.org text/html |
![]() |
Not Found | patchstack.com text/html Inactive LinkNot Archived |
![]() |
There are currently no QIDs associated with this CVE
Known Affected Configurations (CPE V2.3)
Type | Vendor | Product | Version | Update | Edition | Language |
---|---|---|---|---|---|---|
Application | Blazzdev | Rate My Post - Wp Rating System | All | All | All | All |
- cpe:2.3:a:blazzdev:rate_my_post_-_wp_rating_system:*:*:*:*:*:wordpress:*:*:
Discovery Credit
Vulnerability discovered by Nguy Minh Tuan (Patchstack Alliance)
Social Mentions
Source | Title | Posted (UTC) |
---|---|---|
![]() |
CVE-2022-40671 : Cross-Site Request Forgery CSRF vulnerability in Rate my Post – WP Rating System plugin <= 3.3.4… twitter.com/i/web/status/1… | 2022-09-23 15:09:17 |
![]() |
Wordpress - CVE-2022-40671: patchstack.com/database/vulne… | 2022-09-23 17:01:05 |
![]() |
CVE-2022-40671 | 2022-09-23 16:38:22 |