cve/2022/CVE-2022-0188.md

18 lines
694 B
Markdown
Raw Normal View History

2024-05-25 21:48:12 +02:00
### [CVE-2022-0188](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-0188)
![](https://img.shields.io/static/v1?label=Product&message=CMP&color=blue)
![](https://img.shields.io/static/v1?label=Version&message=0%3C%204.0.19%20&color=brighgreen)
![](https://img.shields.io/static/v1?label=Vulnerability&message=CWE-306%20Missing%20Authentication%20for%20Critical%20Function&color=brighgreen)
### Description
The CMP WordPress plugin before 4.0.19 allows any user, even not logged in, to arbitrarily change the coming soon page layout.
### POC
#### Reference
- https://wpscan.com/vulnerability/50b6f770-6f53-41ef-b2f3-2a58e9afd332
#### Github
- https://github.com/ARPSyndicate/cvemon