CVE-2022-1424

The Ask me WordPress theme before 6.8.2 does not perform CSRF checks for any of its AJAX actions, allowing an attacker to trick logged in users to perform various actions on their behalf on the site.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:2code:ask_me:*:*:*:*:*:wordpress:*:*

History

14 Jun 2022, 19:00

Type Values Removed Values Added
First Time 2code
2code ask Me
References (MISC) https://wpscan.com/vulnerability/147b4097-dec8-4542-b122-7b237db81c05 - (MISC) https://wpscan.com/vulnerability/147b4097-dec8-4542-b122-7b237db81c05 - Exploit, Third Party Advisory
CPE cpe:2.3:a:2code:ask_me:*:*:*:*:*:wordpress:*:*
CVSS v2 : unknown
v3 : unknown
v2 : 4.3
v3 : 6.5

08 Jun 2022, 10:15

Type Values Removed Values Added
New CVE

Information

Published : 2022-06-08 10:15

Updated : 2023-12-10 14:22


NVD link : CVE-2022-1424

Mitre link : CVE-2022-1424

CVE.ORG link : CVE-2022-1424


JSON object : View

Products Affected

2code

  • ask_me
CWE
CWE-352

Cross-Site Request Forgery (CSRF)