First published: Fri Nov 18 2022(Updated: )
Multiple Cross-Site Request Forgery (CSRF) vulnerabilities in Creative Mail plugin <= 1.5.4 on WordPress.
Credit: audit@patchstack.com audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Constant Contact Creative Mail | <=1.5.4 |
Update to 1.6.0 or higher version.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-44740 is considered a medium severity vulnerability due to its potential for exploitation via Cross-Site Request Forgery.
To fix CVE-2022-44740, update the Creative Mail plugin to version 1.5.5 or later.
CVE-2022-44740 affects users of the Creative Mail plugin versions 1.5.4 and earlier on WordPress.
CVE-2022-44740 is a Cross-Site Request Forgery (CSRF) vulnerability.
Yes, CVE-2022-44740 can potentially be exploited remotely by attackers to perform unauthorized actions.