### [CVE-2022-1672](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-1672) ![](https://img.shields.io/static/v1?label=Product&message=Insights%20from%20Google%20PageSpeed&color=blue) ![](https://img.shields.io/static/v1?label=Version&message=4.0.7%3C%204.0.7%20&color=brighgreen) ![](https://img.shields.io/static/v1?label=Vulnerability&message=CWE-352%20Cross-Site%20Request%20Forgery%20(CSRF)&color=brighgreen) ### Description The Insights from Google PageSpeed WordPress plugin before 4.0.7 does not verify for CSRF before doing various actions such as deleting Custom URLs, which could allow attackers to make a logged in admin perform such actions via CSRF attacks ### POC #### Reference - https://wpscan.com/vulnerability/5c5955d7-24f0-45e6-9c27-78ef50446dad #### Github No PoCs found on GitHub currently.