CyberRota Analysis
AI analysis pending.
CVE
CVE-2022-1791
Severity
HIGH
CVSS
8.1
EPSS
0.52%
WordPress
Original NVD Description
The One Click Plugin Updater WordPress plugin through 2.4.14 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack and disable / hide the badge of the available updates and the related check.