First published: Fri Nov 18 2022(Updated: )
Cross-Site Request Forgery (CSRF) vulnerability in REST API Authentication plugin <= 2.4.0 on WordPress.
Credit: audit@patchstack.com audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
MiniOrange WordPress REST API Authentication | <=2.4.0 |
Update to 2.4.1 or higher version.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2022-45073 is high with a CVSS score of 8.8.
The CSRF vulnerability in REST API Authentication plugin <= 2.4.0 allows attackers to perform unauthorized actions on WordPress sites by tricking authenticated users into executing malicious requests.
Yes, a patch is available for CVE-2022-45073. Please refer to the provided reference for more information.
To fix the CSRF vulnerability, update the REST API Authentication plugin to version 2.4.1 or newer.
The Common Weakness Enumeration (CWE) ID for CVE-2022-45073 is 352.