Vulnerability Description
The Donation Button WordPress plugin through 4.0.0 does not properly check for privileges and nonce tokens in its "donation_button_twilio_send_test_sms" AJAX action, which may allow any users with an account on the affected site, like subscribers, to use the plugin's Twilio integration to send SMSes to arbitrary phone numbers.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Donation Button Project | Donation Button | <= 4.0.0 |
References
- https://wpscan.com/vulnerability/6a3bcfb3-3ede-459d-969f-b7b30dafd098ExploitThird Party Advisory
- https://wpscan.com/vulnerability/6a3bcfb3-3ede-459d-969f-b7b30dafd098ExploitThird Party Advisory
FAQ
What is CVE-2022-4004?
CVE-2022-4004 is a vulnerability with a CVSS score of 4.3 (MEDIUM). The Donation Button WordPress plugin through 4.0.0 does not properly check for privileges and nonce tokens in its "donation_button_twilio_send_test_sms" AJAX action, which may allow any users with an ...
How severe is CVE-2022-4004?
CVE-2022-4004 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-4004?
Check the references section above for vendor advisories and patch information. Affected products include: Donation Button Project Donation Button.