CVE-2022-43492: WordPress Comments – wpDiscuz plugin 7.4.2 - Auth. Insecure Direct Object References (IDOR) vulnerability
Published Nov 18, 2022
·Updated
Auth. (subscriber+) Insecure Direct Object References (IDOR) vulnerability in Comments – wpDiscuz plugin 7.4.2 on WordPress.
Affected Software
1 affected component
gVectors Wpdiscuz Wordpress=7.4.2
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
wordpress/wpDiscuz pluginto a version that resolves this vulnerability.Fixed in 7.5
Event History
Nov 18, 2022
CVE Published
via MITRE·10:08 PM
Data Sourced
via MITRE·10:08 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·11:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2022-43492.
2
What is the title of the vulnerability?
The title of the vulnerability is Auth. (subscriber+) Insecure Direct Object References (IDOR) vulnerability in Comments – wpDiscuz plugin 7.4.2 on WordPress.
3
What is the severity of CVE-2022-43492?
The severity of CVE-2022-43492 is high with a severity value of 8.8.
4
Which software is affected by CVE-2022-43492?
The wpDiscuz plugin version 7.4.2 on WordPress is affected by CVE-2022-43492.
5
How can I fix the CVE-2022-43492 vulnerability?
To fix the CVE-2022-43492 vulnerability, update the wpDiscuz plugin to a version that is not affected by the vulnerability.