← back
CVE-2022-3622

Blog2Social <= 6.9.11 - Missing Authorization to Authenticated (Subscriber+) Settings Update

CVSS 4.1 MEDIUMEPSS 0.6%CWE-862
Vexday Risk Score
13Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 4.1EPSS 0.6%KEV nãoPoC Nuclei Metasploit Patch
Lifecycle
20 Oct 2023Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
The Blog2Social plugin for WordPress is vulnerable to authorization bypass due to missing capability checks in versions up to, and including, 6.9.11. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to change some plugin settings intended to be modifiable by admins only.
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:N/I:L/A:N

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →