CVE-2022-3024

CVE-2022-3024: Simple Bitcoin Faucets <= 1.7.0 - Unauthorised AJAX Call to Stored XSS

Vendor Unknown
Product Bitcoin Satoshi Tools : Faucets, Visitor Rewarder, Satoshi Games, Referral Program
Weakness CWE-863 · Incorrect authorization
Published September 26, 2022
Last update May 22, 2025

CVSS base score

What the vulnerability does

01Description

The Simple Bitcoin Faucets WordPress plugin through 1.7.0 does not have any authorisation and CSRF in an AJAX action, allowing any authenticated users, such as subscribers to call it and add/delete/edit Bonds. Furthermore, due to the lack of sanitisation and escaping, it could also lead to Stored Cross-Site Scripting issues

Key dates

02Disclosure timeline

September 26, 2022 CVE published
May 22, 2025 Record updated