CVE-2022-40218: WordPress TH Advance Product Search plugin <= 1.1.4 - Unauthenticated Plugin Settings Change vulnerability
Published May 8, 2024
·Updated
Missing Authorization vulnerability in ThemeHunk Advance WordPress Search Plugin.This issue affects Advance WordPress Search Plugin: from n/a through 1.1.4.
Affected Software
3 affected components
ThemeHunk Advance WordPress Search Plugin<=1.1.4
ThemeHunk TH Advance Product Search plugin<=1.1.4
ThemeHunk Advance Product Search Wordpress<1.1.5
Remediation
Information
Update to 1.1.5 or a higher version.
Event History
May 8, 2024
CVE Published
via MITRE·11:57 AM
Data Sourced
via MITRE·11:57 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·12:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2022-40218?
CVE-2022-40218 is classified as a medium-severity vulnerability.
2
What kind of vulnerability is CVE-2022-40218?
CVE-2022-40218 is a missing authorization vulnerability in the ThemeHunk Advance WordPress Search Plugin.
3
What versions are affected by CVE-2022-40218?
CVE-2022-40218 affects the ThemeHunk Advance WordPress Search Plugin versions up to and including 1.1.4.
4
How do I fix CVE-2022-40218?
To fix CVE-2022-40218, update the ThemeHunk Advance WordPress Search Plugin to the latest version that addresses this vulnerability.
5
What impact does CVE-2022-40218 have on my website?
CVE-2022-40218 could allow unauthorized users to change plugin settings, leading to potential website compromise.