CVE-2022-45069 MEDIUM

CVE-2022-45069: WordPress Crowdsignal Dashboard plugin <= 3.0.9 - Privilege Escalation vulnerability

Vendor Automattic, Inc.
Product Crowdsignal Dashboard – Polls, Surveys & more (WordPress plugin)
Weakness CWE-264
Published November 17, 2022
Last update April 28, 2026

CVSS base score

6.3/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality Low
Integrity Low

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

What the vulnerability does

01Description

Auth. (contributor+) Privilege Escalation vulnerability in Crowdsignal Dashboard plugin <= 3.0.9 on WordPress.

Explanation of Vulnerability in Simple Terms

02Summary

The Crowdsignal Dashboard plugin for WordPress contains an authorization flaw that allows authenticated users with low privileges to read, modify, or delete data they should not have access to. The vulnerability affects versions up to and including 3.0.9. An attacker with a basic WordPress user account can exploit this without user interaction to access or alter sensitive poll and survey information.

What an attacker can do

03Attacker Capabilities

Read, modify, or delete polls and survey data belonging to other users or the site.

Potential impact on your site

04Site Impact

Unauthorized users can access, alter, or destroy poll and survey data, compromising data integrity and user trust.

Conditions required to exploit

05Prerequisites

Attacker must have a low-privilege WordPress user account (e.g., subscriber or contributor role).

Key dates

06Disclosure timeline

November 17, 2022 CVE published
April 28, 2026 Record updated

Related vulnerabilities

08Related CVE