External initialization of trusted variables or data stores vulnerability exists in WordPress Popular Posts 6.0.5 and earlier, therefore the vulnerable product accepts untrusted external inputs to update certain internal variables. As a result, the number of views for an article may be manipulated through a crafted input.
References
Link | Resource |
---|---|
https://github.com/cabrerahector/wordpress-popular-posts/ | Third Party Advisory |
https://jvn.jp/en/jp/JVN13927745/index.html | Third Party Advisory |
https://wordpress.org/plugins/wordpress-popular-posts/ | Product |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: jpcert
Published: 2022-12-07T00:00:00
Updated: 2022-12-07T00:00:00
Reserved: 2022-11-16T00:00:00
Link: CVE-2022-43468
JSON object: View
NVD Information
Status : Analyzed
Published: 2022-12-07T04:15:10.723
Modified: 2022-12-09T00:28:47.283
Link: CVE-2022-43468
JSON object: View
Redhat Information
No data.
CWE