PoC Index

CVE-2022-0163

MEDIUM 6.5EPSS 1.0%

The Smart Forms WordPress plugin before 2.6.71 does not have authorisation in its rednao_smart_forms_entries_list AJAX action, allowing any authenticated users, such as subscriber, to download arbitrary form's data, which could include sensitive information such as PII depending on the form.

CVSS v3.1
6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVSS v2.0
4.0 MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
EPSS
0.99% chance of exploitation in the next 30 days, 60th percentile
Published
2022-03-07
Updated
2024-08-02

Proof-of-concept exploits (1)

References

Related