Limited Black Friday Offer:
Sitemap by click5 < 1.0.36 - Unauthenticated Arbitrary Options Update CVE-2022-0952 Scanner
Sitemap by click5 < 1.0.36 allows unauthenticated Arbitrary Options Update vulnerability.
Short Info
Level
High
Type
Single Scan
Can be used by
Asset Owner
Estimated Time
10 sec
Scan only one
Domain, Ipv4
Parent Category
Sitemap by click5 < 1.0.36 - Unauthenticated Arbitrary Options Update CVE-2022-0952 Scanner Detail
The Sitemap by click5 WordPress plugin before 1.0.36 does not have authorisation and CSRF checks when updating options via a REST endpoint, and does not ensure that the option to be updated belongs to the plugin. As a result, unauthenticated attackers could change arbitrary blog options, such as the users_can_register and default_role, allowing them to create a new admin account and take over the blog.