Vulnerabilities > CVE-2022-3151 - Unspecified vulnerability in WP Custom Cursors Project WP Custom Cursors

047910
CVSS 4.3 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
LOW
Availability impact
NONE
network
low complexity
wp-custom-cursors-project

Summary

The WP Custom Cursors WordPress plugin before 3.0.1 does not have CSRF check in place when deleting cursors, which could allow attackers to made a logged in admin delete arbitrary cursors via a CSRF attack.

Vulnerable Configurations

Part Description Count
Application
Wp_Custom_Cursors_Project
1