CVE-2022-44737: WordPress All In One WP Security plugin <= 5.1.0 - Multiple Cross-Site Request Forgery (CSRF) vulnerabilities
Multiple Cross-Site Request Forgery vulnerabilities in All-In-One Security (AIOS) – Security and Firewall (WordPress plugin) <= 5.1.0 on WordPress.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
wordpress/All-In-One Security (AIOS) – Security and Firewallto a version that resolves this vulnerability.Fixed in 5.1.1
Event History
Frequently Asked Questions
What is CVE-2022-44737?
CVE-2022-44737 refers to Multiple Cross-Site Request Forgery vulnerabilities in All-In-One Security (AIOS) – Security and Firewall (WordPress plugin) <= 5.1.0 on WordPress.
What is the severity of CVE-2022-44737?
The severity of CVE-2022-44737 is high with a CVSS score of 8.8.
Which software versions are affected by CVE-2022-44737?
All-In-One Security (AIOS) – Security and Firewall (WordPress plugin) version up to and including 5.1.0 on WordPress are affected by CVE-2022-44737.
How can I fix CVE-2022-44737?
To fix CVE-2022-44737, upgrade All-In-One Security (AIOS) – Security and Firewall (WordPress plugin) to a version higher than 5.1.0.
What is the CWE ID for CVE-2022-44737?
The CWE ID for CVE-2022-44737 is 352.