Description
Cross-Site Request Forgery (CSRF) vulnerability in WordPlus Better Messages plugin <= 1.9.9.148 at WordPress allows attackers to upload files. File attachment to messages must be activated.
No analysis available yet.
Remediation
Vendor Solution
Update to 1.9.9.149 or higher version.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-33792 | Cross-Site Request Forgery (CSRF) vulnerability in WordPlus Better Messages plugin <= 1.9.9.148 at WordPress allows attackers to upload files. File attachment to messages must be activated. |
References
History
Thu, 20 Feb 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: Patchstack
Published:
Updated: 2025-02-20T20:17:45.347Z
Reserved: 2022-04-18T00:00:00.000Z
Link: CVE-2022-29454
Updated: 2024-08-03T06:26:05.159Z
Status : Modified
Published: 2022-07-20T19:15:14.347
Modified: 2024-11-21T06:59:07.243
Link: CVE-2022-29454
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD