Fiche vulnérabilité
CVE-2022-1589 : faille élevée wpexperts all in one login (CVSS 7.5)
Description
The Change wp-admin login WordPress plugin before 1.1.0 does not properly check for authorisation and is also missing CSRF check when updating its settings, which could allow unauthenticated users to change the settings. The attacked could also be performed via a CSRF vector
En bref
- Sévérité
- Élevée (CVSS 7.5)
- Vecteur CVSS
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
- Exploitation active
- Non signalée par la CISA
- Publication
- 30 mai 2022
- Dernière mise à jour
- 17 juin 2026
Produits concernés
- wpexperts all in one login