CVE-2022-3427: Corner Ad <= 1.0.56 - Cross-Site Request Forgery
The Corner Ad plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0.56. This is due to missing or incorrect nonce validation on its corneradsettingspage function. This makes it possible for unauthenticated attackers to trigger the deletion of ads via forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2022-3427?
CVE-2022-3427 is a vulnerability in the Corner Ad plugin for WordPress, allowing unauthenticated attackers to trigger the deletion of ads.
How severe is the vulnerability CVE-2022-3427?
The severity of CVE-2022-3427 is high with a CVSS score of 6.5.
Which software versions are affected by CVE-2022-3427?
Versions up to and including 1.0.56 of the Corner Ad plugin for WordPress are affected by CVE-2022-3427.
How can the vulnerability CVE-2022-3427 be fixed?
To fix the vulnerability CVE-2022-3427, it is recommended to update the Corner Ad plugin for WordPress to a version that includes the necessary nonce validation.
Where can I find more information about CVE-2022-3427?
You can find more information about CVE-2022-3427 at these references: [link1], [link2], [link3].