First published: Fri Aug 05 2022(Updated: )
Broken Authentication vulnerability in JumpDEMAND Inc. ActiveDEMAND plugin <= 0.2.27 at WordPress allows unauthenticated post update/create/delete.
Credit: audit@patchstack.com audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Activedemand | <=0.2.27 |
Update to 0.2.28 or a higher version.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-36296 is identified as a critical vulnerability due to its potential to allow unauthenticated users to create, update, or delete posts.
To fix CVE-2022-36296, update the ActiveDEMAND plugin to version 0.2.28 or later, which addresses the authentication issues.
CVE-2022-36296 affects versions of the ActiveDEMAND plugin up to and including 0.2.27.
CVE-2022-36296 is categorized as a Broken Authentication vulnerability.
Yes, CVE-2022-36296 specifically affects the ActiveDEMAND plugin for WordPress.