Vulnerability Details CVE-2022-1092
The myCred WordPress plugin before 2.4.3.1 does not have authorisation and CSRF checks in its mycred-tools-import-export AJAX action, allowing any authenticated user to call and and retrieve the list of email address present in the blog
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 29.3%
CVSS Severity
CVSS v3 Score 4.3
CVSS v2 Score 4.0
Products affected by CVE-2022-1092
-
cpe:2.3:a:mycred:mycred:-
-
cpe:2.3:a:mycred:mycred:2.0
-
cpe:2.3:a:mycred:mycred:2.0.1
-
cpe:2.3:a:mycred:mycred:2.0.2
-
cpe:2.3:a:mycred:mycred:2.1
-
cpe:2.3:a:mycred:mycred:2.1.0.1
-
cpe:2.3:a:mycred:mycred:2.1.0.2
-
cpe:2.3:a:mycred:mycred:2.1.0.3
-
cpe:2.3:a:mycred:mycred:2.1.1
-
cpe:2.3:a:mycred:mycred:2.2
-
cpe:2.3:a:mycred:mycred:2.3
-
cpe:2.3:a:mycred:mycred:2.3.1
-
cpe:2.3:a:mycred:mycred:2.3.2
-
cpe:2.3:a:mycred:mycred:2.4.1
-
cpe:2.3:a:mycred:mycred:2.4.2
-
cpe:2.3:a:mycred:mycred:2.4.3
-
cpe:2.3:a:mycred:mycred:2.4.3.1