Headline
CVE-2022-45073: WordPress REST API Authentication plugin <= 2.4.0 - Cross-Site Request Forgery (CSRF) vulnerability - Patchstack
Cross-Site Request Forgery (CSRF) vulnerability in REST API Authentication plugin <= 2.4.0 on WordPress.
Verified
Fixed
5.4
CVSS 3.1 score Medium severity
Report
Monitoring Not reported to be exploited
Vulnerable versions
<= 2.4.0
PSID
9a7eb49bf153
Classification
Cross Site Request Forgery (CSRF)
OWASP Top 10
A5: Broken Access Control
Publicly disclosed
2022-11-09
Details
Cross-Site Request Forgery (CSRF) vulnerability leading to plugin settings change discovered by Lana Codes (Patchstack Alliance) in WordPress REST API Authentication plugin (versions <= 2.4.0).
Solution
Update the WordPress WordPress REST API Authentication plugin to the latest available version (at least 2.4.1).
References