CVE-2022-30337Cross-Site Request Forgery in WP Meta SEO

Severity
4.3MEDIUMNVD
CNA5.4
EPSS
0.1%
top 71.88%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJul 21
Latest updateJul 22

Description

Cross-Site Request Forgery (CSRF) vulnerability in JoomUnited WP Meta SEO plugin <= 4.4.8 at WordPress allows an attacker to update the social settings.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:NExploitability: 2.8 | Impact: 1.4

Affected Packages2 packages

CVEListV5joomunited/wp_meta_seo4.4.8

Patches

🔴Vulnerability Details

2
GHSA
GHSA-rx95-3qjc-3hfc: Cross-Site Request Forgery (CSRF) vulnerability in JoomUnited WP Meta SEO plugin <= 42022-07-22
CVEList
WordPress WP Meta SEO plugin <= 4.4.8 - Social Settings Update vis Cross-Site Request Forgery (CSRF) vulnerability2022-07-21
CVE-2022-30337 — Cross-Site Request Forgery | cvebase