Vulnerability Description
The Backup, Restore and Migrate WordPress Sites With the XCloner Plugin WordPress plugin before 4.3.6 does not have authorisation and CSRF checks when resetting its settings, allowing unauthenticated attackers to reset them, including generating a new backup encryption key.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Watchful | Xcloner | < 4.3.6 |
Related Weaknesses (CWE)
References
- https://wpscan.com/vulnerability/9567d295-43c7-4e59-9283-c7726f16d40bExploitThird Party Advisory
- https://wpscan.com/vulnerability/9567d295-43c7-4e59-9283-c7726f16d40bExploitThird Party Advisory
FAQ
What is CVE-2022-0444?
CVE-2022-0444 is a vulnerability with a CVSS score of 4.3 (MEDIUM). The Backup, Restore and Migrate WordPress Sites With the XCloner Plugin WordPress plugin before 4.3.6 does not have authorisation and CSRF checks when resetting its settings, allowing unauthenticated ...
How severe is CVE-2022-0444?
CVE-2022-0444 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-0444?
Check the references section above for vendor advisories and patch information. Affected products include: Watchful Xcloner.