Medium severity4.3NVD Advisory· Published Jun 27, 2022· Updated Jun 17, 2026
CVE-2022-1885
CVE-2022-1885
Description
The Cimy Header Image Rotator WordPress plugin through 6.1.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3<=6.1.1+ 1 more
- (no CPE)range: <=6.1.1
- (no CPE)range: <=6.1.1
- cpe:2.3:a:cimy_header_image_rotator_project:cimy_header_image_rotator:*:*:*:*:*:wordpress:*:*Range: <=6.1.1
Patches
Vulnerability mechanics
References
1- wpscan.com/vulnerability/8416cbcf-086d-42ff-b2a4-f3954c8ff0c8nvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.