CVE-2022-1589

Change WP Admin Login <= 1.0.9 - Missing Authorization Checks

mediumIncorrect Authorization
5.4
CVSS Score
5.4
CVSS Score
medium
Severity
1.1.0
Patched in
624d
Time to patch

Description

The Change WP Admin Login WordPress plugin before 1.1.0 does not properly check for authorisation and is also missing CSRF check when updating its settings, which could allow unauthenticated users to change the settings. The attacked could also be performed via a CSRF vector

CVSS Vector Breakdown

CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:H/A:N
Attack Vector
Network
Attack Complexity
High
Privileges Required
Low
User Interaction
Required
Scope
Unchanged
Low
Confidentiality
High
Integrity
None
Availability

Technical Details

Affected versions<=1.0.9
PublishedMay 9, 2022
Last updatedJanuary 22, 2024
Affected pluginchange-wp-admin-login

What Changed in the Fix

Changes introduced in v1.1.0

Trac

Check if your site is affected.

Run a free security audit to detect vulnerable plugins, outdated versions, and misconfigurations.