WP Customer Area, CVE-2022-4745
- CVE, Research URL
- Home page URL
- Application
- Published on
- Feb 13, 2023
- Research Description
- The WP Customer Area WordPress plugin before 8.1.4 does not have CSRF checks when performing some actions such as chmod, mkdir and copy, which could allow attackers to make a logged-in admin perform them and create arbitrary folders, copy file for example.
- Affected versions
-
Min -, max 8.1.4.
- Status
-
vulnerable