First published: Mon Dec 12 2022(Updated: )
The WP Tools Increase Maximum Limits, Repair, Server PHP Info, Javascript errors, File Permissions, Transients, Error Log WordPress plugin before 3.43 does not have proper authorisation and CSRF in an AJAX action, allowing any authenticated users, such as subscriber to call it and install and activate arbitrary plugins from wordpress.org
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
Array-tools | <3.43 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2022-3881 is considered to be medium due to the potential impact of unauthorized access by authenticated users.
To fix CVE-2022-3881, update the WP Tools plugin to version 3.43 or later.
CVE-2022-3881 affects any authenticated users, including subscribers, on WordPress sites utilizing vulnerable versions of the WP Tools plugin.
CVE-2022-3881 can allow attackers to execute unauthorized AJAX actions, leading to potential data exposure and manipulation.
No, CVE-2022-3881 is not classified as a zero-day vulnerability since it has been publicly disclosed and a fix is available.