CVE-2022-1779

Description

The Auto Delete Posts WordPress plugin through 1.3.0 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack and delete specific posts, categories and attachments at once.

CvssV3 impact

Could not find any metrics

CvssV2 impact

AccessComplexity

MEDIUM

ConfidentialityImpact

NONE

AvailabilityImpact

PARTIAL

IntegrityImpact

PARTIAL

BaseScore

5.800000190734863

VectorString

AV:N/AC:M/Au:N/C:N/I:P/A:P

Version

2.0

AccessVector

NETWORK

Authentication

NONE