Vulnerabilities > CVE-2022-1791 - Unspecified vulnerability in ONE Click Plugin Updater Project ONE Click Plugin Updater

047910
CVSS 8.1 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
HIGH
Availability impact
HIGH
network
low complexity
one-click-plugin-updater-project

Summary

The One Click Plugin Updater WordPress plugin through 2.4.14 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack and disable / hide the badge of the available updates and the related check.

Vulnerable Configurations

Part Description Count
Application
One_Click_Plugin_Updater_Project
48