CVE-2022-2123

Severity CVSS v4.0:
Pending analysis
Type:
CWE-352 Cross-Site Request Forgery (CSRF)
Publication date:
11/07/2022
Last modified:
15/07/2022

Description

The WP Opt-in WordPress plugin through 1.4.1 is vulnerable to CSRF which allows changed plugin settings and can be used for sending spam emails.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:wp_opt-in_project:wp_opt-in:*:*:*:*:*:wordpress:*:* 1.4.1 (including)