CVE-2022-40223

Nonce token leakage and missing authorization in SearchWP premium plugin <= 4.2.5 on WordPress leading to plugin settings change.
Configurations

Configuration 1 (hide)

cpe:2.3:a:searchwp:searchwp:*:*:*:*:*:wordpress:*:*

History

09 Nov 2022, 13:56

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 4.3
CWE CWE-862
References (CONFIRM) https://patchstack.com/database/vulnerability/searchwp/wordpress-searchwp-premium-plugin-4-2-5-broken-authentication-vulnerability?_s_id=cve - (CONFIRM) https://patchstack.com/database/vulnerability/searchwp/wordpress-searchwp-premium-plugin-4-2-5-broken-authentication-vulnerability?_s_id=cve - Third Party Advisory
References (CONFIRM) https://searchwp.com/documentation/changelog/ - (CONFIRM) https://searchwp.com/documentation/changelog/ - Release Notes, Vendor Advisory
CPE cpe:2.3:a:searchwp:searchwp:*:*:*:*:*:wordpress:*:*

08 Nov 2022, 19:25

Type Values Removed Values Added
New CVE

Information

Published : 2022-11-08 19:15

Updated : 2024-02-04 22:51


NVD link : CVE-2022-40223

Mitre link : CVE-2022-40223

CVE.ORG link : CVE-2022-40223


JSON object : View

Products Affected

searchwp

  • searchwp
CWE
CWE-862

Missing Authorization