CVE-2022-29489: WordPress Sucuri Security plugin <= 1.8.33 - Cross-Site Request Forgery (CSRF) vulnerability
Published Sep 16, 2022
·Updated
Cross-Site Request Forgery (CSRF) vulnerability in Sucuri Security plugin <= 1.8.33 at WordPress leading to Event log entry creation.
Affected Software
1 affected component
Sucuri Security Wordpress<=1.8.33
Remediation
Information
Update to 1.8.34 or higher version.
Event History
Sep 16, 2022
CVE Published
via MITRE·08:22 PM
Data Sourced
via MITRE·08:22 PM
RemedyDescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2022-29489?
CVE-2022-29489 is rated as a medium severity vulnerability due to its potential to allow unauthorized actions on behalf of users.
2
How do I fix CVE-2022-29489?
To fix CVE-2022-29489, update the Sucuri Security plugin to version 1.8.34 or later.
3
What type of vulnerability is CVE-2022-29489?
CVE-2022-29489 is a Cross-Site Request Forgery (CSRF) vulnerability affecting the Sucuri Security plugin.
4
What are the consequences of CVE-2022-29489?
Exploitation of CVE-2022-29489 could lead to unauthorized creation of event log entries.
5
Which versions are affected by CVE-2022-29489?
CVE-2022-29489 affects the Sucuri Security plugin versions up to and including 1.8.33.