CVE Database
/

CVE-2022-0541

Back to search

CVE-2022-0541

Published: Apr 25, 2022

Modified: Aug 2, 2024

PUBLISHED

Description

The flo-launch WordPress plugin before 2.4.1 injects code into wp-config.php when creating a cloned site, allowing any attacker to initiate a new site install by setting the flo_custom_table_prefix cookie to an arbitrary value.

VendorProductVersions

Unknown

flo-launch

affected
2.4.1 - < 2.4.1

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now