CVE Database
/

CVE-2022-0952

Back to search

CVE-2022-0952

Published: May 2, 2022

Modified: Aug 2, 2024

PUBLISHED

Description

The Sitemap by click5 WordPress plugin before 1.0.36 does not have authorisation and CSRF checks when updating options via a REST endpoint, and does not ensure that the option to be updated belongs to the plugin. As a result, unauthenticated attackers could change arbitrary blog options, such as the users_can_register and default_role, allowing them to create a new admin account and take over the blog.

VendorProductVersions

Unknown

Sitemap by click5

affected
0 - < 1.0.36

References

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now