Headline
CVE-2022-36358: WordPress SEO Scout plugin <= 0.9.83 - Cross-Site Request Forgery (CSRF) vulnerability - Patchstack
Cross-Site Request Forgery (CSRF) vulnerability in SEO Scout plugin <= 0.9.83 at WordPress allows attackers to trick users with administrative rights to unintentionally change the plugin settings.
Verified
Not fixed
5.4
CVSS 3.1 score Medium severity
Monitoring Coming soon
Vulnerable versions
<= 0.9.83
PSID
453afcf86c8b
Classification
Cross Site Request Forgery (CSRF)
OWASP Top 10
A5: Broken Access Control
Publicly disclosed
2022-08-25
Details
Cross-Site Request Forgery (CSRF) vulnerability leading to plugin settings change discovered by ptsfence (Patchstack Alliance) in WordPress SEO Scout plugin (versions <= 0.9.83).
Solution
Deactivate and delete. This plugin has been closed as of August 24, 2022 and is not available for download. This closure is temporary, pending a full review.
References