PoC Index

CVE-2022-3082

MEDIUM 6.5EPSS 0.4%

The miniOrange Discord Integration WordPress plugin before 2.1.6 does not have authorisation and CSRF in some of its AJAX actions, allowing any logged in users, such as subscriber to call them, and disable the app for example

CVSS v3.1
6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CVSS v3.1
6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
EPSS
0.43% chance of exploitation in the next 30 days, 36th percentile
Published
2022-10-17
Updated
2025-05-13

Proof-of-concept exploits (1)

References

Related