CVE-2022-43468
External initialization of trusted variables or data stores vulnerability exists in WordPress Popular Posts 6.0.5 and earlier, therefore the vulnerable product accepts untrusted external inputs to update certain internal variables.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.85%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
External initialization of trusted variables or data stores vulnerability exists in WordPress Popular Posts 6.0.5 and earlier, therefore the vulnerable product accepts untrusted external inputs to update certain internal variables. As a result, the number of views for an article may be manipulated through a crafted input.
- CVSS 3.1
- 7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
- EPSS
- 0.85% probability · 56th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-665
- Affected
- wordpress popular posts project/wordpress popular posts
- Source
- vultures@jpcert.or.jp
References
- https://github.com/cabrerahector/wordpress-popular-posts/Third Party Advisory
- https://jvn.jp/en/jp/JVN13927745/index.htmlThird Party Advisory
- https://wordpress.org/plugins/wordpress-popular-posts/Product
- https://github.com/cabrerahector/wordpress-popular-posts/Third Party Advisory
- https://jvn.jp/en/jp/JVN13927745/index.htmlThird Party Advisory
- https://wordpress.org/plugins/wordpress-popular-posts/Product
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.