The Autolinks WordPress plugin through 1.0.1 does not have CSRF check in place when updating its settings, and does not sanitise as well as escape them, which could allow attackers to perform Stored Cross-Site scripting against a logged in admin via a CSRF attack
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published: 2022-04-18T17:10:56

Updated: 2024-08-02T23:55:23.670Z

Reserved: 2022-03-28T00:00:00

Link: CVE-2022-1112

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2022-04-18T18:15:09.117

Modified: 2022-04-27T12:43:37.227

Link: CVE-2022-1112

cve-icon Redhat

No data.