logo
Vulnerability feed
CONTRIBUTE

Vulnerability

warn

CVE-2022-3894

Reference to the description:

https://nvd.nist.gov/vuln/detail/CVE-2022-3894

Description:
The WP OAuth Server (OAuth Authentication) WordPress plugin before 4.2.5 does not have CSRF check when deleting a client, and does not ensure that the object to be deleted is actually a client, which could allow attackers to make a logged in admin delete arbitrary client and post via a CSRF attack.
Last updated date:
03/24/2023
Type:
exploit
Confidence:
HIGH
Date of publishing:
03/24/2023
Reference url to background

https://wpscan.com/vulnerability/298487b2-4141-4c9f-9bb2-e1450aefc1a8

Vulnerability FeedContributorsAboutBlog

@inTheWild

©2024

Privacy Policy