CVE-2022-2388: WP Coder < 2.5.3 - Code Deletion via CSRF
Published Aug 22, 2022
·Updated
The WP Coder WordPress plugin before 2.5.3 does not have CSRF check in place when deleting code created by the plugin, which could allow attackers to make a logged in admin delete arbitrary ones via a CSRF attack
Affected Software
1 affected component
Wow-Company WP Coder WordPress<2.5.3
Event History
Aug 22, 2022
CVE Published
via MITRE·03:02 PM
Data Sourced
via MITRE·03:02 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID for the WP Coder WordPress plugin vulnerability?
The vulnerability ID for the WP Coder WordPress plugin vulnerability is CVE-2022-2388.
2
What is the severity of CVE-2022-2388?
The severity of CVE-2022-2388 is medium (6.5).
3
What is the affected software for CVE-2022-2388?
The affected software for CVE-2022-2388 is Wow-company Wp Coder plugin version up to 2.5.3 in WordPress.
4
How does the WP Coder WordPress plugin vulnerability occur?
The WP Coder WordPress plugin vulnerability occurs due to the lack of CSRF check when deleting code created by the plugin.
5
How can attackers exploit CVE-2022-2388?
Attackers can exploit CVE-2022-2388 by performing a CSRF attack to make a logged-in admin delete arbitrary code.