{"api_version":"1","generated_at":"2026-07-23T15:28:20+00:00","cve":"CVE-2022-43468","urls":{"html":"https://cve.report/CVE-2022-43468","api":"https://cve.report/api/cve/CVE-2022-43468.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2022-43468","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2022-43468"},"summary":{"title":"CVE-2022-43468","description":"External initialization of trusted variables or data stores vulnerability exists in WordPress Popular Posts 6.0.5 and earlier, therefore the vulnerable product accepts untrusted external inputs to update certain internal variables. As a result, the number of views for an article may be manipulated through a crafted input.","state":"PUBLIC","assigner":"vultures@jpcert.or.jp","published_at":"2022-12-07 04:15:00","updated_at":"2022-12-09 00:28:00"},"problem_types":["CWE-665"],"metrics":[],"references":[{"url":"https://github.com/cabrerahector/wordpress-popular-posts/","name":"https://github.com/cabrerahector/wordpress-popular-posts/","refsource":"MISC","tags":[],"title":"GitHub - cabrerahector/wordpress-popular-posts: WordPress Popular Posts - A highly customizable WordPress widget that displays your most popular posts.","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://jvn.jp/en/jp/JVN13927745/index.html","name":"https://jvn.jp/en/jp/JVN13927745/index.html","refsource":"MISC","tags":[],"title":"JVN#13927745: WordPress Plugin \"WordPress Popular Posts\" accepts untrusted external inputs to update certain internal variables","mime":"text/xml","httpstatus":"200","archivestatus":"404"},{"url":"https://wordpress.org/plugins/wordpress-popular-posts/","name":"https://wordpress.org/plugins/wordpress-popular-posts/","refsource":"MISC","tags":[],"title":"WordPress Popular Posts – WordPress plugin | WordPress.org","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2022-43468","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2022-43468","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2022","cve_id":"43468","vulnerable":"1","versionEndIncluding":"6.0.5","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"wordpress_popular_posts_project","cpe5":"wordpress_popular_posts","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"wordpress","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"data_type":"CVE","data_format":"MITRE","data_version":"4.0","CVE_data_meta":{"ID":"CVE-2022-43468","ASSIGNER":"vultures@jpcert.or.jp","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"vendor_name":"Hector Cabrera","product":{"product_data":[{"product_name":"WordPress Popular Posts","version":{"version_data":[{"version_value":"6.0.5 and earlier"}]}}]}}]}},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"External Initialization of Trusted Variables or Data Stores"}]}]},"references":{"reference_data":[{"url":"https://wordpress.org/plugins/wordpress-popular-posts/","refsource":"MISC","name":"https://wordpress.org/plugins/wordpress-popular-posts/"},{"url":"https://github.com/cabrerahector/wordpress-popular-posts/","refsource":"MISC","name":"https://github.com/cabrerahector/wordpress-popular-posts/"},{"url":"https://jvn.jp/en/jp/JVN13927745/index.html","refsource":"MISC","name":"https://jvn.jp/en/jp/JVN13927745/index.html"}]},"description":{"description_data":[{"lang":"eng","value":"External initialization of trusted variables or data stores vulnerability exists in WordPress Popular Posts 6.0.5 and earlier, therefore the vulnerable product accepts untrusted external inputs to update certain internal variables. As a result, the number of views for an article may be manipulated through a crafted input."}]}},"nvd":{"publishedDate":"2022-12-07 04:15:00","lastModifiedDate":"2022-12-09 00:28:00","problem_types":["CWE-665"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE","baseScore":7.5,"baseSeverity":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:wordpress_popular_posts_project:wordpress_popular_posts:*:*:*:*:*:wordpress:*:*","versionEndIncluding":"6.0.5","cpe_name":[]}]}]}},"legacy_mitre":{"record":null,"notes":[]}}}