QID 150498
Date Published: 2022-04-13
QID 150498: WordPress AnyComment Plugin: Arbitrary HyperComments Import/Revert via CSRF Vulnerability (CVE-2022-0134)
AnyComment is a plugin for WordPress, it allows users to easily add their comments via social networks.
The plugin does not have CSRF checks in the Import and Revert HyperComments features, allowing attackers to make logged in admin perform such actions via a CSRF attack.
Affected Versions:
AnyComment WordPress plugin before 0.2.18
QID Detection Logic (Unauthenticated) :
The QID sends a HTTP GET request with specially crafted payload, where vulnerable servers will make a DNS query that will trigger Qualys periscope detection mechanism.
Successful exploitation could allow an attacker to execute arbitrary JavaScript code in the context of the interface or allow the attacker to access sensitive, browser-based information.
Solution
Customers are advised to upgrade to AnyComment 0.2.18 or later version to remediate this vulnerability. For more information regarding this vulnerability please refer WPScan.
Vendor References
CVEs related to QID 150498
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| WPScan |
|
||
| WordPress |
|