CVE-2022-1612: Webriti SMTP Mail <= 1.0 - Arbitrary Settings Update via CSRF
The Webriti SMTP Mail WordPress plugin through 1.0 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-1612?
CVE-2022-1612 has been classified as a high severity vulnerability due to the potential for CSRF attacks impacting WordPress admin settings.
How do I fix CVE-2022-1612?
To fix CVE-2022-1612, update the Webriti SMTP Mail plugin to a version beyond 1.0 or implement CSRF protection in the settings update functionality.
What type of attack is possible with CVE-2022-1612?
CVE-2022-1612 allows for Cross-Site Request Forgery (CSRF) attacks, which can allow unauthorized changes to admin settings.
Who is affected by CVE-2022-1612?
All WordPress sites using the Webriti SMTP Mail plugin version 1.0 or lower are affected by CVE-2022-1612.
Is there a known exploit for CVE-2022-1612?
While there is no public exploit reported for CVE-2022-1612, the lack of CSRF checks poses a significant risk for exploitation.