Due to missing checks the Change Uploaded File Permissions WordPress plugin through 4.0.0 is vulnerable to CSRF attacks. This can be used to change the file and folder permissions of any folder. This could be problematic when specific files like ini files are made readable for everyone due to this.
References
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: WPScan

Published: 2022-06-13T12:42:55

Updated: 2022-06-13T12:42:55

Reserved: 2022-05-18T00:00:00


Link: CVE-2022-1788

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2022-06-13T13:15:12.837

Modified: 2022-06-21T16:41:45.163


Link: CVE-2022-1788

JSON object: View

cve-icon Redhat Information

No data.

CWE