AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2022-3850

MEDIUM · CVSS 4.3 EPSS 0.27%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2022-11-28 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2022-3850
Severity
MEDIUM
CVSS
4.3
EPSS
0.27%
WordPress

Original NVD Description

The Find and Replace All WordPress plugin before 1.3 does not have CSRF check when replacing string, which could allow attackers to make a logged admin replace arbitrary string in database tables via a CSRF attack

Related CVEs

Other vulnerabilities affecting the same vendor(s)