CVE-2022-3489
- Reference to the description:
- Description:
- The WP Hide WordPress plugin through 0.0.2 does not have authorisation and CSRF checks in place when updating the custom_wpadmin_slug settings, allowing unauthenticated attackers to update it with a crafted request
- Last updated date:
- 07/21/2023
- Type:
- exploit
- Confidence:
- HIGH
- Date of publishing:
- 11/10/2022
- Reference url to background
https://wpscan.com/vulnerability/36d78b6c-0da5-44f8-b7b3-eae78edac505