CVE-2022-1818

CVE-2022-1818: Multi-page Toolkit <= 2.6 - Arbitrary Settings Update to Stored XSS via CSRF

Vendor Unknown
Product Multi-page Toolkit
Weakness CWE-352 · CSRF
Published June 20, 2022
Last update August 3, 2024

CVSS base score

What the vulnerability does

01Description

The Multi-page Toolkit WordPress plugin through 2.6 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack and lead to Stored Cross-Site Scripting due to the lack of sanitisation and escaping as well

Key dates

02Disclosure timeline

June 20, 2022 CVE published
August 3, 2024 Record updated

Related vulnerabilities

04Related CVE