CVE-2022-29454: WordPress Better Messages plugin <= 1.9.9.148 - Cross-Site Request Forgery (CSRF) vulnerability
Cross-Site Request Forgery (CSRF) vulnerability in WordPlus Better Messages plugin <= 1.9.9.148 at WordPress allows attackers to upload files. File attachment to messages must be activated.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2022-29454?
CVE-2022-29454 is classified as a cross-site request forgery (CSRF) vulnerability that can have a medium severity impact.
How do I fix CVE-2022-29454?
To mitigate CVE-2022-29454, update the WordPlus Better Messages plugin to version 1.9.9.149 or later.
What impact does CVE-2022-29454 have on affected systems?
CVE-2022-29454 allows attackers to exploit the vulnerability to upload files on systems running vulnerable versions of the plugin.
Which versions of the WordPlus Better Messages plugin are affected by CVE-2022-29454?
CVE-2022-29454 affects WordPlus Better Messages plugin versions up to and including 1.9.9.148.
What mitigation strategies can be employed besides updating for CVE-2022-29454?
Besides updating, consider disabling file attachments to messages until the plugin is secured against the vulnerability.