CVE-2022-3747: Becustom <= 1.0.5.2 - Cross-Site Request Forgery
The Becustom plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0.5.2. This is due to missing nonce validation when saving the plugin's settings. This makes it possible for unauthenticated attackers to update the plugin's settings like bethemeurlslug, replacedthemeauthor, and bethemelabel to name a few, via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-3747?
CVE-2022-3747 is a vulnerability in the Becustom plugin for WordPress that allows unauthenticated attackers to update the plugin's settings.
What is the severity of CVE-2022-3747?
CVE-2022-3747 has a severity rating of 6.5, which is considered high.
How does CVE-2022-3747 affect the Becustom plugin?
CVE-2022-3747 affects versions up to and including 1.0.5.2 of the Becustom plugin for WordPress.
How can attackers exploit CVE-2022-3747?
Attackers can exploit CVE-2022-3747 by performing Cross-Site Request Forgery attacks to update the plugin's settings.
Is there a fix for CVE-2022-3747?
Yes, an update to the latest version of the Becustom plugin should fix CVE-2022-3747.