Description
The WP Cerber Security, Anti-spam & Malware Scan WordPress plugin before 9.3.3 does not properly block access to the REST API users endpoint when the blog is in a subdirectory, which could allow attackers to bypass the restriction in place and list users
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-51762 | The WP Cerber Security, Anti-spam & Malware Scan WordPress plugin before 9.3.3 does not properly block access to the REST API users endpoint when the blog is in a subdirectory, which could allow attackers to bypass the restriction in place and list users |
References
History
Thu, 10 Apr 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2025-04-10T18:51:59.902Z
Reserved: 2022-12-12T09:02:24.033Z
Link: CVE-2022-4417
Updated: 2024-08-03T01:41:44.631Z
Status : Modified
Published: 2023-01-02T22:15:18.110
Modified: 2025-04-10T19:15:54.483
Link: CVE-2022-4417
No data.
OpenCVE Enrichment
No data.
Weaknesses
No weakness.
EUVD