CVE-2022-38104

Auth. WordPress Options Change (siteurl, users_can_register, default_role, admin_email and new_admin_email) vulnerability in Biplob Adhikari's Accordions – Multiple Accordions or FAQs Builder plugin (versions <= 2.0.3 on WordPress.
Configurations

Configuration 1 (hide)

cpe:2.3:a:oxilab:accordions:*:*:*:*:*:wordpress:*:*

History

24 Oct 2022, 15:23

Type Values Removed Values Added
CWE NVD-CWE-Other
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.2
CPE cpe:2.3:a:oxilab:accordions:*:*:*:*:*:wordpress:*:*
References (CONFIRM) https://wordpress.org/plugins/accordions-or-faqs/#developers - (CONFIRM) https://wordpress.org/plugins/accordions-or-faqs/#developers - Product, Third Party Advisory
References (CONFIRM) https://patchstack.com/database/vulnerability/accordions-or-faqs/wordpress-accordions-plugin-2-0-3-authenticated-wordpress-options-change-vulnerability?_s_id=cve - (CONFIRM) https://patchstack.com/database/vulnerability/accordions-or-faqs/wordpress-accordions-plugin-2-0-3-authenticated-wordpress-options-change-vulnerability?_s_id=cve - Third Party Advisory

21 Oct 2022, 16:48

Type Values Removed Values Added
New CVE

Information

Published : 2022-10-21 16:15

Updated : 2024-02-04 22:51


NVD link : CVE-2022-38104

Mitre link : CVE-2022-38104

CVE.ORG link : CVE-2022-38104


JSON object : View

Products Affected

oxilab

  • accordions
CWE
NVD-CWE-Other CWE-264

Permissions, Privileges, and Access Controls