Vulnerability Description
The Clerk WordPress plugin before 4.0.0 is affected by time-based attacks in the validation function for all API requests due to the usage of comparison operators to verify API keys against the ones stored in the site options.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Clerk | Clerk.Io | < 4.0.0 |
Related Weaknesses (CWE)
References
- https://wpscan.com/vulnerability/7920c1c1-709d-4b1f-ac08-f0a02ddb329cExploitThird Party Advisory
- https://wpscan.com/vulnerability/7920c1c1-709d-4b1f-ac08-f0a02ddb329cExploitThird Party Advisory
FAQ
What is CVE-2022-3907?
CVE-2022-3907 is a vulnerability with a CVSS score of 7.5 (HIGH). The Clerk WordPress plugin before 4.0.0 is affected by time-based attacks in the validation function for all API requests due to the usage of comparison operators to verify API keys against the ones s...
How severe is CVE-2022-3907?
CVE-2022-3907 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-3907?
Check the references section above for vendor advisories and patch information. Affected products include: Clerk Clerk.Io.