Vulnerability Description
Unauthenticated Sensitive Information Disclosure vulnerability in WP Libre Form 2 plugin <= 2.0.8 at WordPress allows attackers to list and delete submissions. Affects only versions from 2.0.0 to 2.0.8.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Wp Libre Form Project | Wp Libre Form | >= 2.0.0, <= 2.0.8 |
Related Weaknesses (CWE)
References
- https://github.com/libreform/libreform/pull/54/filesPatchThird Party Advisory
- https://patchstack.com/database/vulnerability/libreform/wordpress-wp-libre-form-Third Party Advisory
- https://github.com/libreform/libreform/pull/54/filesPatchThird Party Advisory
- https://patchstack.com/database/vulnerability/libreform/wordpress-wp-libre-form-Third Party Advisory
FAQ
What is CVE-2022-34867?
CVE-2022-34867 is a vulnerability with a CVSS score of 7.3 (HIGH). Unauthenticated Sensitive Information Disclosure vulnerability in WP Libre Form 2 plugin <= 2.0.8 at WordPress allows attackers to list and delete submissions. Affects only versions from 2.0.0 to 2.0....
How severe is CVE-2022-34867?
CVE-2022-34867 has been rated HIGH with a CVSS base score of 7.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-34867?
Check the references section above for vendor advisories and patch information. Affected products include: Wp Libre Form Project Wp Libre Form.