CVE-2022-45073: WordPress REST API Authentication plugin <= 2.4.0 - Cross-Site Request Forgery (CSRF) vulnerability
Cross-Site Request Forgery (CSRF) vulnerability in REST API Authentication plugin <= 2.4.0 on WordPress.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress REST API Authentication pluginto a version that resolves this vulnerability.Fixed in 2.4.1
Event History
Frequently Asked Questions
What is the severity of CVE-2022-45073?
The severity of CVE-2022-45073 is high with a CVSS score of 8.8.
How does the CSRF vulnerability in REST API Authentication plugin <= 2.4.0 affect WordPress?
The CSRF vulnerability in REST API Authentication plugin <= 2.4.0 allows attackers to perform unauthorized actions on WordPress sites by tricking authenticated users into executing malicious requests.
Is there a patch available for CVE-2022-45073?
Yes, a patch is available for CVE-2022-45073. Please refer to the provided reference for more information.
How can I fix the CSRF vulnerability in REST API Authentication plugin <= 2.4.0?
To fix the CSRF vulnerability, update the REST API Authentication plugin to version 2.4.1 or newer.
What is the Common Weakness Enumeration (CWE) ID for CVE-2022-45073?
The Common Weakness Enumeration (CWE) ID for CVE-2022-45073 is 352.