Vulnerability Description
The Admin Management Xtended WordPress plugin before 2.4.5 does not have CSRF checks in some of its AJAX actions, allowing attackers to make a logged users with the right capabilities to call them. This can lead to changes in post status (draft, published), slug, post date, comment status (enabled, disabled) and more.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Admin Management Xtended Project | Admin Management Xtended | < 2.4.5 |
Related Weaknesses (CWE)
References
- https://wpscan.com/vulnerability/4a36e876-7e3b-4a81-9f16-9ff5fbb20dd6ExploitThird Party Advisory
- https://wpscan.com/vulnerability/4a36e876-7e3b-4a81-9f16-9ff5fbb20dd6ExploitThird Party Advisory
FAQ
What is CVE-2022-1599?
CVE-2022-1599 is a vulnerability with a CVSS score of 6.5 (MEDIUM). The Admin Management Xtended WordPress plugin before 2.4.5 does not have CSRF checks in some of its AJAX actions, allowing attackers to make a logged users with the right capabilities to call them. Th...
How severe is CVE-2022-1599?
CVE-2022-1599 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-1599?
Check the references section above for vendor advisories and patch information. Affected products include: Admin Management Xtended Project Admin Management Xtended.