Vulnerability Description
Due to missing checks the Change Uploaded File Permissions WordPress plugin through 4.0.0 is vulnerable to CSRF attacks. This can be used to change the file and folder permissions of any folder. This could be problematic when specific files like ini files are made readable for everyone due to this.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Change Uploaded File Permissions Project | Change Uploaded File Permissions | <= 4.0.0 |
Related Weaknesses (CWE)
References
- https://wpscan.com/vulnerability/c39719e5-dadd-4414-a96d-5e70a1e3d462ExploitThird Party Advisory
- https://wpscan.com/vulnerability/c39719e5-dadd-4414-a96d-5e70a1e3d462ExploitThird Party Advisory
FAQ
What is CVE-2022-1788?
CVE-2022-1788 is a vulnerability with a CVSS score of 6.5 (MEDIUM). Due to missing checks the Change Uploaded File Permissions WordPress plugin through 4.0.0 is vulnerable to CSRF attacks. This can be used to change the file and folder permissions of any folder. This ...
How severe is CVE-2022-1788?
CVE-2022-1788 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-1788?
Check the references section above for vendor advisories and patch information. Affected products include: Change Uploaded File Permissions Project Change Uploaded File Permissions.