VYPR
Medium severity5.3NVD Advisory· Published Mar 27, 2022· Updated Jun 17, 2026

CVE-2022-26254

CVE-2022-26254

Description

WoWonder The Ultimate PHP Social Network Platform v4.0.0 was discovered to contain an access control issue which allows unauthenticated attackers to arbitrarily change group ID names.

Affected products

3
  • WoWonder/WoWonder2 versions
    cpe:2.3:a:wowonder:wowonder:4.0:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:wowonder:wowonder:4.0:*:*:*:*:*:*:*
    • (no CPE)range: =4.0.0
  • WoWonder/The Ultimate PHP Social Network Platformdescription

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.