CVE-2022-38062: WordPress Download Theme Plugin <= 1.0.9 is vulnerable to Cross Site Request Forgery (CSRF)
Published Jul 17, 2023
·Updated
Cross-Site Request Forgery (CSRF) vulnerability in Metagauss Download Theme plugin <= 1.0.9 versions.
Affected Software
1 affected component
Metagauss Download Theme Wordpress<=1.0.9
Remediation
Information
Update to 1.1.0 or a higher version.
Event History
Jul 17, 2023
CVE Published
via MITRE·03:20 PM
Data Sourced
via MITRE·03:20 PM
RemedyDescriptionSeverityWeakness
Data Sourced
04:15 PM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2022-38062?
CVE-2022-38062 is a Cross-Site Request Forgery (CSRF) vulnerability in the Metagauss Download Theme plugin versions <= 1.0.9.
2
What is the severity of CVE-2022-38062?
CVE-2022-38062 has a severity rating of 8.8 (high).
3
How does CVE-2022-38062 affect Metagauss Download Theme plugin?
CVE-2022-38062 affects Metagauss Download Theme plugin versions <= 1.0.9.
4
How can I fix CVE-2022-38062 in Metagauss Download Theme plugin?
To fix CVE-2022-38062 in Metagauss Download Theme plugin, update to a version higher than 1.0.9.
5
What is the Common Weakness Enumeration (CWE) ID for CVE-2022-38062?
The CWE ID for CVE-2022-38062 is CWE-352 (Cross-Site Request Forgery).