CVE-2022-2245: Counter Box < 1.2.1 - Arbitrary Counter Activation/Deactivation via CSRF
Published Aug 1, 2022
·Updated
The Counter Box WordPress plugin before 1.2.1 is lacking CSRF check when activating and deactivating counters, which could allow attackers to make a logged in admin perform such actions via CSRF attacks
Affected Software
1 affected component
Wow-Company Counter Box WordPress<1.2.1
Event History
Aug 1, 2022
CVE Published
via MITRE·12:50 PM
Data Sourced
via MITRE·12:50 PM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2022-2245?
CVE-2022-2245 is a vulnerability found in the Counter Box WordPress plugin before version 1.2.1.
2
What is the severity of CVE-2022-2245?
CVE-2022-2245 has a severity rating of 8.8, which is considered high.
3
How does CVE-2022-2245 affect Counter Box WordPress plugin?
CVE-2022-2245 affects Counter Box WordPress plugin versions before 1.2.1 by lacking CSRF checks when activating and deactivating counters.
4
How can an attacker exploit CVE-2022-2245?
An attacker can exploit CVE-2022-2245 by making a logged in admin perform actions via CSRF attacks.
5
Is there a fix available for CVE-2022-2245?
Yes, the fix for CVE-2022-2245 is to update the Counter Box WordPress plugin to version 1.2.1 or newer.