HIGH

CVE-2022-0952

CVSS v3

8.8

HIGH

EPSS Score

89.2%

exploit probability

CISA KEV

No

known exploited

Exploitation

SSVC status

Description

The Sitemap by click5 WordPress plugin before 1.0.36 does not have authorisation and CSRF checks when updating options via a REST endpoint, and does not ensure that the option to be updated belongs to the plugin. As a result, unauthenticated attackers could change arbitrary blog options, such as the users_can_register and default_role, allowing them to create a new admin account and take over the blog.

Technical details

Published
5/2/2022

Frequently asked questions

What is CVE-2022-0952?

The Sitemap by click5 WordPress plugin before 1.0.36 does not have authorisation and CSRF checks when updating options via a REST endpoint, and does not ensure that the option to be updated belongs to the plugin. As a result, unauthenticated attackers could change arbitrary blog options, such as the users_can_register and default_role, allowing them to create a new admin account and take over the blog.

Is CVE-2022-0952 actively exploited?

Active exploitation of CVE-2022-0952 has not been confirmed. The EPSS score is 89.2%, indicating the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2022-0952?

CVE-2022-0952 has a CVSS v3 base score of 8.8 (HIGH severity).

Is CVE-2022-0952 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.