First published: Mon Aug 01 2022(Updated: )
The Counter Box WordPress plugin before 1.2.1 is lacking CSRF check when activating and deactivating counters, which could allow attackers to make a logged in admin perform such actions via CSRF attacks
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
Wow-company Counter Box | <1.2.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-2245 is a vulnerability found in the Counter Box WordPress plugin before version 1.2.1.
CVE-2022-2245 has a severity rating of 8.8, which is considered high.
CVE-2022-2245 affects Counter Box WordPress plugin versions before 1.2.1 by lacking CSRF checks when activating and deactivating counters.
An attacker can exploit CVE-2022-2245 by making a logged in admin perform actions via CSRF attacks.
Yes, the fix for CVE-2022-2245 is to update the Counter Box WordPress plugin to version 1.2.1 or newer.