cve/2022/CVE-2022-3489.md
2024-06-18 02:51:15 +02:00

890 B

CVE-2022-3489

Description

The WP Hide WordPress plugin through 0.0.2 does not have authorisation and CSRF checks in place when updating the custom_wpadmin_slug settings, allowing unauthenticated attackers to update it with a crafted request

POC

Reference

Github

No PoCs found on GitHub currently.