VDB

CVE-2022-0875

CVE-2022-0875 PUBLISHED CVSS 4.300000190734863 MEDIUM

The Google Authenticator WordPress plugin before 1.0.5 does not have CSRF check when saving its settings, and does not sanitise as well as escape them, allowing attackers to make a logged in admin change them and perform Cross-Site Scripting attacks

EPSS 0.43% · 36.7th percentile

Risk Scores

CVSS 3.1
4.300000190734863
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
EPSS Score
0.43%
36.7th percentile

Affected Products

VendorProductVersions
miniorangegoogle_authenticator0
UnknownGoogle Authenticator1.0.5

Timeline

  • Jun 27, 2022 CVE Published
  • Jun 28, 2022 EPSS Score
  • Aug 16, 2022 EPSS Score
  • Oct 3, 2022 EPSS Score
  • Nov 20, 2022 EPSS Score
  • Jan 7, 2023 EPSS Score
  • Mar 7, 2023 EPSS Score
  • Apr 13, 2023 EPSS Score
  • May 31, 2023 EPSS Score
  • Jul 18, 2023 EPSS Score
  • Sep 4, 2023 EPSS Score
  • Oct 22, 2023 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›