VDB
CVE-2022-0875
CVE-2022-0875
PUBLISHED
CVSS 4.300000190734863 MEDIUM
The Google Authenticator WordPress plugin before 1.0.5 does not have CSRF check when saving its settings, and does not sanitise as well as escape them, allowing attackers to make a logged in admin change them and perform Cross-Site Scripting attacks
EPSS 0.43% · 36.7th percentile
Risk Scores
CVSS 3.1
4.300000190734863
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
EPSS Score
0.43%
36.7th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| miniorange | google_authenticator | 0 |
| Unknown | Google Authenticator | 1.0.5 |
Timeline
- Jun 27, 2022 CVE Published
- Jun 28, 2022 EPSS Score
- Aug 16, 2022 EPSS Score
- Oct 3, 2022 EPSS Score
- Nov 20, 2022 EPSS Score
- Jan 7, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 13, 2023 EPSS Score
- May 31, 2023 EPSS Score
- Jul 18, 2023 EPSS Score
- Sep 4, 2023 EPSS Score
- Oct 22, 2023 EPSS Score