CVE-2022-1092: myCred < 2.4.4 - Subscriber+ Import/Export to Email Address Disclosure
The myCred WordPress plugin before 2.4.3.1 does not have authorisation and CSRF checks in its mycred-tools-import-export AJAX action, allowing any authenticated user to call and and retrieve the list of email address present in the blog
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-1092?
CVE-2022-1092 is a vulnerability in the myCred WordPress plugin before version 2.4.3.1 that allows any authenticated user to retrieve a list of email addresses present in the blog.
What is the severity of CVE-2022-1092?
The severity of CVE-2022-1092 is medium with a severity value of 4.3.
How can I fix CVE-2022-1092?
To fix CVE-2022-1092, update the myCred WordPress plugin to version 2.4.3.1 or higher.
What are the affected software versions for CVE-2022-1092?
The affected software versions for CVE-2022-1092 include myCred WordPress plugin versions up to and excluding 2.4.4.
Are there any references for CVE-2022-1092?
Yes, you can find more information about CVE-2022-1092 at the following reference: https://wpscan.com/vulnerability/95759d5c-8802-4493-b7e5-7f2bc546af61