Vulnerabilities > CVE-2022-1709 - Unspecified vulnerability in GTI Throws Spam Away
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
NONE Integrity impact
LOW Availability impact
NONE Summary
The Throws SPAM Away WordPress plugin before 3.3.1 does not have CSRF checks in place when deleting comments (either all, spam, or pending), allowing attackers to make a logged in admin delete comments via a CSRF attack
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |