VYPR
Unrated severityNVD Advisory· Published Apr 18, 2022· Updated Aug 2, 2024

Autolinks <= 1.0.1 - Stored Cross-Site Scripting via CSRF

CVE-2022-1112

Description

The Autolinks WordPress plugin through 1.0.1 does not have CSRF check in place when updating its settings, and does not sanitise as well as escape them, which could allow attackers to perform Stored Cross-Site scripting against a logged in admin via a CSRF attack

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

2
  • Autolinks/Autolinksllm-fuzzy2 versions
    <=1.0.1+ 1 more
    • (no CPE)range: <=1.0.1
    • (no CPE)range: 1.0.1

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.