Vulnerabilities > CVE-2022-3489 - Missing Authorization vulnerability in Weberge WP Hide 0.0.2

047910
CVSS 5.3 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
LOW
Availability impact
NONE
network
low complexity
weberge
CWE-862

Summary

The WP Hide WordPress plugin through 0.0.2 does not have authorisation and CSRF checks in place when updating the custom_wpadmin_slug settings, allowing unauthenticated attackers to update it with a crafted request

Vulnerable Configurations

Part Description Count
Application
Weberge
1

Common Weakness Enumeration (CWE)