CVE-2022-36296: WordPress ActiveDEMAND plugin <= 0.2.27 - Broken Authentication vulnerability
Published Aug 5, 2022
·Updated
Broken Authentication vulnerability in JumpDEMAND Inc. ActiveDEMAND plugin <= 0.2.27 at WordPress allows unauthenticated post update/create/delete.
Affected Software
1 affected component
JumpDEMAND Activedemand Wordpress<=0.2.27
Remediation
Information
Update to 0.2.28 or a higher version.
Event History
Aug 5, 2022
CVE Published
via MITRE·03:08 PM
Data Sourced
via MITRE·03:08 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2022-36296?
CVE-2022-36296 is identified as a critical vulnerability due to its potential to allow unauthenticated users to create, update, or delete posts.
2
How do I fix CVE-2022-36296?
To fix CVE-2022-36296, update the ActiveDEMAND plugin to version 0.2.28 or later, which addresses the authentication issues.
3
What versions of the ActiveDEMAND plugin are affected by CVE-2022-36296?
CVE-2022-36296 affects versions of the ActiveDEMAND plugin up to and including 0.2.27.
4
What type of vulnerability is CVE-2022-36296?
CVE-2022-36296 is categorized as a Broken Authentication vulnerability.
5
Is CVE-2022-36296 specific to WordPress?
Yes, CVE-2022-36296 specifically affects the ActiveDEMAND plugin for WordPress.