CVE-2022-33974: WordPress Custom Twitter Feeds (Tweets Widget) Plugin <= 1.8.4 is vulnerable to Cross Site Request Forgery (CSRF)
Published May 29, 2023
·Updated
Cross-Site Request Forgery (CSRF) vulnerability in Smash Balloon Custom Twitter Feeds (Tweets Widget) plugin <= 1.8.4 versions.
Affected Software
1 affected component
Smashballoon Custom Twitter Feeds Wordpress<=1.8.4
Remediation
Information
Update to 2.0 or a higher version.
Event History
May 29, 2023
CVE Published
via MITRE·12:10 AM
Data Sourced
via MITRE·12:10 AM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the CVE ID for this vulnerability?
The CVE ID for this vulnerability is CVE-2022-33974.
2
What is the title of this vulnerability?
The title of this vulnerability is Cross-Site Request Forgery (CSRF) vulnerability in Smash Balloon Custom Twitter Feeds (Tweets Widget).
3
What is the severity of CVE-2022-33974?
The severity of CVE-2022-33974 is high with a severity value of 8.8.
4
What software versions are affected by this vulnerability?
The Smash Balloon Custom Twitter Feeds (Tweets Widget) plugin <= 1.8.4 versions are affected by this vulnerability.
5
How do I fix CVE-2022-33974?
To fix CVE-2022-33974, update the Smash Balloon Custom Twitter Feeds (Tweets Widget) plugin to version 1.8.5 or higher.