CVE-2022-4974 - Freemius WordPress CSRF & Info Disclosure Vulnerability

2 days ago 2
ARTICLE AD BOX
CVE ID : CVE-2022-4974
Published : Oct. 16, 2024, 7:15 a.m. | 24 minutes ago
Description : The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions in versions up to, and including 2.4.2. Any WordPress plugin or theme running a version of Freemius less than 2.4.3 is vulnerable.
Severity: 6.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Read Entire Article