CVE-2022-45364: WordPress Drag and Drop Multiple File Upload – Contact Form 7 Plugin <= 1.3.6.5 is vulnerable to Cross Site Request Forgery (CSRF)
Published May 24, 2023
·Updated
Cross-Site Request Forgery (CSRF) vulnerability in Glen Don L. Mongaya Drag and Drop Multiple File Upload – Contact Form 7 plugin <= 1.3.6.5 versions.
Affected Software
1 affected component
codedropz Drag And Drop Multiple File Upload - Contact Form 7 Wordpress<=1.3.6.5
Remediation
Information
Update to 1.3.6.6 or a higher version.
Event History
May 24, 2023
CVE Published
via MITRE·03:48 PM
Data Sourced
via MITRE·03:48 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the CVE ID for the vulnerability?
The CVE ID for the vulnerability is CVE-2022-45364.
2
What is the title of the vulnerability?
The title of the vulnerability is Cross-Site Request Forgery (CSRF) vulnerability in Glen Don L. Mongaya Drag and Drop Multiple File Upload – Contact Form 7 plugin <= 1.3.6.5 versions.
3
What is the severity of CVE-2022-45364?
The severity of CVE-2022-45364 is high with a severity score of 8.8.
4
What is the affected software?
The affected software is Codedropz Drag And Drop Multiple File Upload - Contact Form 7 plugin version up to and including 1.3.6.5.
5
How can I fix the CSRF vulnerability in Glen Don L. Mongaya Drag and Drop Multiple File Upload – Contact Form 7 plugin?
To fix the CSRF vulnerability in Glen Don L. Mongaya Drag and Drop Multiple File Upload – Contact Form 7 plugin, update to version 1.3.6.6 or later.