CVE-2022-47165 MEDIUM

CVE-2022-47165: WordPress CoSchedule Plugin <= 3.3.8 is vulnerable to Cross Site Request Forgery (CSRF)

Vendor Coschedule
Product CoSchedule
Weakness CWE-352 · CSRF
Published May 25, 2023
Last update April 28, 2026

CVSS base score

4.3/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality None
Integrity Low

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

What the vulnerability does

01Description

Cross-Site Request Forgery (CSRF) vulnerability in CoSchedule plugin <= 3.3.8 versions.

Explanation of Vulnerability in Simple Terms

02Summary

CoSchedule versions up to 3.3.8 are vulnerable to cross-site request forgery (CSRF) attacks. An attacker can craft a malicious webpage that, when visited by a logged-in CoSchedule user, performs unwanted actions on their account without their knowledge. The vulnerability requires the victim to be authenticated and does not affect data confidentiality or availability.

What an attacker can do

03Attacker Capabilities

Perform unwanted actions on a logged-in user's CoSchedule account without their consent.

Potential impact on your site

04Site Impact

Users' CoSchedule accounts can be manipulated by attackers through forged requests if users visit untrusted sites while logged in.

Conditions required to exploit

05Prerequisites

Victim must be logged into CoSchedule; attacker must trick them into visiting a malicious webpage.

Key dates

06Disclosure timeline

May 25, 2023 CVE published
April 28, 2026 Record updated

Related vulnerabilities

08Related CVE