AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2022-4417

MEDIUM · CVSS 5.3 EPSS 0.67%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2023-01-02 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2022-4417
Severity
MEDIUM
CVSS
5.3
EPSS
0.67%
WordPress

Original NVD Description

The WP Cerber Security, Anti-spam & Malware Scan WordPress plugin before 9.3.3 does not properly block access to the REST API users endpoint when the blog is in a subdirectory, which could allow attackers to bypass the restriction in place and list users