CVE-2022-1761

Severity CVSS v4.0:
Pending analysis
Type:
CWE-352 Cross-Site Request Forgery (CSRF)
Publication date:
13/06/2022
Last modified:
07/11/2023

Description

The Peter’s Collaboration E-mails WordPress plugin through 2.2.0 is vulnerable to CSRF due to missing nonce checks. This allows the change of its settings, which can be used to lower the required user level, change texts, the used email address and more.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:peter\'s_collaboration_e-mails_project:peter\'s_collaboration_e-mails:*:*:*:*:*:wordpress:*:* 2.2.0 (including)