CVE-2022-2350
- Reference to the description:
- Description:
- The Disable User Login WordPress plugin through 1.0.1 does not have authorisation and CSRF checks when updating its settings, allowing unauthenticated attackers to block (or unblock) users at will.
- Last updated date:
- 07/14/2023
- Type:
- exploit
- Confidence:
- HIGH
- Date of publishing:
- 10/11/2022
- Reference url to background
https://wpscan.com/vulnerability/de28543b-c110-4a9f-bfe9-febccfba3a96