First published: Mon Nov 21 2022(Updated: )
The Event Monster WordPress plugin before 1.2.0 does not have CSRF check when deleting visitors, which could allow attackers to make logged in admin delete arbitrary visitors via a CSRF attack
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
Awplife Event Monster | <1.2.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of the Event Monster WordPress plugin is CVE-2022-3336.
The severity of CVE-2022-3336 is medium, with a CVSS score of 4.3.
CVE-2022-3336 allows attackers to make logged in admin delete arbitrary visitors via a CSRF attack.
The affected version of the Event Monster WordPress plugin is before 1.2.0.
Yes, the fix for CVE-2022-3336 is to update the Event Monster WordPress plugin to version 1.2.0 or above.