CVE-2022-4555
Published on: Not Yet Published
Last Modified on: 12/20/2022 05:49:00 PM UTC
Certain versions of Wp Shamsi from Wpvar contain the following vulnerability:
The WP Shamsi plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the deactivate() function hooked via init() in versions up to, and including, 4.1.0. This makes it possible for unauthenticated attackers to deactivate arbitrary plugins on the site. This can be used to deactivate security plugins that aids in exploiting other vulnerabilities.
- CVE-2022-4555 has been assigned by
[email protected] to track the vulnerability - currently rated as MEDIUM severity.
- Affected Vendor/Software:
wpvar - WP Shamsi – افزونه تاریخ شمسی و فارسی ساز وردپرس version = *
CVSS3 Score: 5.3 - MEDIUM
Attack Vector ⓘ |
Attack Complexity |
Privileges Required |
User Interaction |
---|---|---|---|
NETWORK | LOW | NONE | NONE |
Scope | Confidentiality Impact |
Integrity Impact |
Availability Impact |
UNCHANGED | NONE | LOW | NONE |
CVE References
Description | Tags ⓘ | Link |
---|---|---|
WP Shamsi <= 4.1.0 - Missing Authorization to Arbitrary Plugin Deactivation | www.wordfence.com text/html |
![]() |
403 Forbidden | plugins.trac.wordpress.org text/html Inactive LinkNot Archived |
![]() |
There are currently no QIDs associated with this CVE
Known Affected Configurations (CPE V2.3)
Type | Vendor | Product | Version | Update | Edition | Language |
---|---|---|---|---|---|---|
Application | Wpvar | Wp Shamsi | All | All | All | All |
- cpe:2.3:a:wpvar:wp_shamsi:*:*:*:*:*:wordpress:*:*:
No vendor comments have been submitted for this CVE
Social Mentions
Source | Title | Posted (UTC) |
---|---|---|
![]() |
CVE-2022-4555 : The WP Shamsi plugin for WordPress is vulnerable to authorization bypass due to a missing capabilit… twitter.com/i/web/status/1… | 2022-12-16 14:06:55 |
![]() |
Potentially Critical CVE Detected! CVE-2022-4555 The WP Shamsi plugin for WordPress is vulnerable to authorization… twitter.com/i/web/status/1… | 2022-12-16 14:56:00 |
![]() |
CVE-2022-4555 | 2022-12-16 14:41:13 |