← back
CVE-2022-1765

Hot Linked Image Cacher <= 1.16 - Image upload/cache abuse via CSRF

EPSS 0.6%CWE-352
Vexday Risk Score
3Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS EPSS 0.6%KEV nãoPoC Nuclei Metasploit Patch
Lifecycle
13 Jun 2022Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
The Hot Linked Image Cacher WordPress plugin through 1.16 is vulnerable to CSRF. This can be used to store / cache images from external domains on the server, which could lead to legal risks (due to copyright violations or licensing rules).

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →