CyberRota Analysis
This is a medium severity vulnerability with a CVSS score of 4.3. It affects WordPress.
CVE
CVE-2022-3894
Severity
MEDIUM
CVSS
4.3
EPSS
0.25%
WordPress
Original NVD Description
The WP OAuth Server (OAuth Authentication) WordPress plugin before 4.2.5 does not have CSRF check when deleting a client, and does not ensure that the object to be deleted is actually a client, which could allow attackers to make a logged in admin delete arbitrary client and post via a CSRF attack.
Related CVEs
Other vulnerabilities affecting the same vendor(s)