Vulnerability Description
The Simple Bitcoin Faucets WordPress plugin through 1.7.0 does not have any authorisation and CSRF in an AJAX action, allowing any authenticated users, such as subscribers to call it and add/delete/edit Bonds. Furthermore, due to the lack of sanitisation and escaping, it could also lead to Stored Cross-Site Scripting issues
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Simple Bitcoin Faucets Project | Simple Bitcoin Faucets | <= 1.7.0 |
Related Weaknesses (CWE)
References
- https://wpscan.com/vulnerability/7f43cb8e-0c1b-4528-8c5c-b81ab42778dcExploitThird Party Advisory
- https://wpscan.com/vulnerability/7f43cb8e-0c1b-4528-8c5c-b81ab42778dcExploitThird Party Advisory
FAQ
What is CVE-2022-3024?
CVE-2022-3024 is a vulnerability with a CVSS score of 5.4 (MEDIUM). The Simple Bitcoin Faucets WordPress plugin through 1.7.0 does not have any authorisation and CSRF in an AJAX action, allowing any authenticated users, such as subscribers to call it and add/delete/ed...
How severe is CVE-2022-3024?
CVE-2022-3024 has been rated MEDIUM with a CVSS base score of 5.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-3024?
Check the references section above for vendor advisories and patch information. Affected products include: Simple Bitcoin Faucets Project Simple Bitcoin Faucets.