The Disable User Login WordPress plugin through 1.0.1 does not have authorisation and CSRF checks when updating its settings, allowing unauthenticated attackers to block (or unblock) users at will.
References
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: WPScan

Published: 2022-10-10T00:00:00

Updated: 2022-10-10T00:00:00

Reserved: 2022-07-08T00:00:00


Link: CVE-2022-2350

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2022-10-10T21:15:10.550

Modified: 2023-07-14T18:16:42.230


Link: CVE-2022-2350

JSON object: View

cve-icon Redhat Information

No data.