Vulnerability Description
The WP Coder WordPress plugin before 2.5.3 does not have CSRF check in place when deleting code created by the plugin, which could allow attackers to make a logged in admin delete arbitrary ones via a CSRF attack
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Wow-Company | Wp Coder | < 2.5.3 |
Related Weaknesses (CWE)
References
- https://wpscan.com/vulnerability/50acd35f-eb31-4aba-bf32-b390e9514bebExploitThird Party Advisory
- https://wpscan.com/vulnerability/50acd35f-eb31-4aba-bf32-b390e9514bebExploitThird Party Advisory
FAQ
What is CVE-2022-2388?
CVE-2022-2388 is a vulnerability with a CVSS score of 6.5 (MEDIUM). The WP Coder WordPress plugin before 2.5.3 does not have CSRF check in place when deleting code created by the plugin, which could allow attackers to make a logged in admin delete arbitrary ones via a...
How severe is CVE-2022-2388?
CVE-2022-2388 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-2388?
Check the references section above for vendor advisories and patch information. Affected products include: Wow-Company Wp Coder.