Vulnerability Description
The Counter Box WordPress plugin before 1.2.1 is lacking CSRF check when activating and deactivating counters, which could allow attackers to make a logged in admin perform such actions via CSRF attacks
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Wow-Company | Counter Box | < 1.2.1 |
Related Weaknesses (CWE)
References
- https://wpscan.com/vulnerability/33705003-1f82-4b0c-9b4b-d4de75da309cExploitThird Party Advisory
- https://wpscan.com/vulnerability/33705003-1f82-4b0c-9b4b-d4de75da309cExploitThird Party Advisory
FAQ
What is CVE-2022-2245?
CVE-2022-2245 is a vulnerability with a CVSS score of 8.8 (HIGH). The Counter Box WordPress plugin before 1.2.1 is lacking CSRF check when activating and deactivating counters, which could allow attackers to make a logged in admin perform such actions via CSRF attac...
How severe is CVE-2022-2245?
CVE-2022-2245 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-2245?
Check the references section above for vendor advisories and patch information. Affected products include: Wow-Company Counter Box.