CVE-2022-42884: WordPress WIP Custom Login Plugin <= 1.2.7 is vulnerable to Broken Access Control
Published Jan 17, 2024
·Updated
Missing Authorization vulnerability in ThemeinProgress WIP Custom Login.This issue affects WIP Custom Login: from n/a through 1.2.7.
Affected Software
1 affected component
ThemeinProgress Wip Custom Login Wordpress<=1.2.7
Remediation
Information
Update to 1.2.8 or a higher version.
Event History
Jan 17, 2024
CVE Published
via MITRE·06:17 PM
Data Sourced
via MITRE·06:17 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·07:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2022-42884?
CVE-2022-42884 is classified as a missing authorization vulnerability.
2
How do I fix CVE-2022-42884?
To fix CVE-2022-42884, update the WIP Custom Login plugin to version 1.2.8 or later.
3
Which versions of WIP Custom Login are affected by CVE-2022-42884?
CVE-2022-42884 affects WIP Custom Login versions from n/a up to and including 1.2.7.
4
What type of vulnerability is CVE-2022-42884?
CVE-2022-42884 is a Broken Access Control type vulnerability.
5
Who is impacted by CVE-2022-42884?
Users of the WIP Custom Login plugin in versions up to 1.2.7 are impacted by CVE-2022-42884.