← Back to CVE List

CVE-2022-3999

Published: 2022-12-12T18:15Z
Last Modified: 2024-11-21T07:20Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
The DPD Baltic Shipping WordPress plugin before 1.2.57 does not have authorisation and CSRF in an AJAX action, which could allow any authenticated users, such as subscriber to delete arbitrary options from the blog, which could make the blog unavailable. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt