The New User Approve WordPress plugin before 2.4 does not have CSRF check in place when updating its settings and adding invitation codes, which could allow attackers to add invitation codes (for bypassing the provided restrictions) and to change plugin settings by tricking admin users into visiting specially crafted websites.
References
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: WPScan

Published: 2022-06-27T08:57:11

Updated: 2022-06-27T08:57:11

Reserved: 2022-05-09T00:00:00


Link: CVE-2022-1625

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2022-06-27T09:15:09.323

Modified: 2022-07-07T15:53:00.927


Link: CVE-2022-1625

JSON object: View

cve-icon Redhat Information

No data.

CWE