PoC Index

CVE-2022-3999

HIGH 8.1EPSS 0.4%

The DPD Baltic Shipping WordPress plugin before 1.2.57 does not have authorisation and CSRF in an AJAX action, which could allow any authenticated users, such as subscriber to delete arbitrary options from the blog, which could make the blog unavailable.

CVSS v3.1
8.1 HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
CVSS v3.1
8.1 HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
EPSS
0.42% chance of exploitation in the next 30 days, 35th percentile
Published
2022-12-12
Updated
2025-04-22

Proof-of-concept exploits (1)

References

Related