CVE-2022-0363: myCred < 2.4.4 - Subscriber+ Arbitrary Post Creation
The myCred WordPress plugin before 2.4.3.1 does not have any authorisation and CSRF checks in the mycred-tools-import-export AJAX action, allowing any authenticated users, such as subscribers, to call it and import mycred setup, thus creating badges, managing points or creating arbitrary posts.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-0363?
CVE-2022-0363 is a vulnerability in the myCred WordPress plugin before version 2.4.3.1 that allows authenticated users to import mycred setup and perform tasks they are not authorized to do.
How does CVE-2022-0363 affect my website?
CVE-2022-0363 affects websites that have the myCred plugin installed and have a version before 2.4.3.1. Authenticated users, such as subscribers, can use this vulnerability to exploit the mycred-tools-import-export AJAX action and perform unauthorized actions.
What is the severity of CVE-2022-0363?
CVE-2022-0363 has a severity rating of 4.3 (medium).
How can I fix CVE-2022-0363?
To fix CVE-2022-0363, update the myCred WordPress plugin to version 2.4.3.1 or later.
What can an attacker do with CVE-2022-0363?
With CVE-2022-0363, an authenticated user can call the mycred-tools-import-export AJAX action and import mycred setup, thus being able to create badges, manage points, or create arbitrary posts.