CVE-2022-38454: WordPress Kraken.io Image Optimizer plugin <= 2.6.5 - Cross-Site Request Forgery (CSRF) vulnerability
Published Sep 23, 2022
·Updated
Cross-Site Request Forgery (CSRF) vulnerability in Kraken.io Image Optimizer plugin <= 2.6.5 at WordPress.
Affected Software
1 affected component
Kraken Kraken.io Image Optimizer Wordpress<=2.6.5
Event History
Sep 23, 2022
CVE Published
via MITRE·06:36 PM
Data Sourced
via MITRE·06:36 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2022-38454?
CVE-2022-38454 is classified as a moderate severity Cross-Site Request Forgery (CSRF) vulnerability.
2
How do I fix CVE-2022-38454?
To fix CVE-2022-38454, update the Kraken.io Image Optimizer plugin to a version newer than 2.6.5.
3
What type of vulnerability is CVE-2022-38454?
CVE-2022-38454 is a Cross-Site Request Forgery (CSRF) vulnerability affecting the Kraken.io Image Optimizer plugin.
4
Which versions of the Kraken.io Image Optimizer plugin are affected by CVE-2022-38454?
CVE-2022-38454 affects Kraken.io Image Optimizer plugin versions up to and including 2.6.5.
5
What can an attacker do with CVE-2022-38454?
An attacker exploiting CVE-2022-38454 can potentially perform unauthorized actions on behalf of an authenticated user.