High severity7.1NVD Advisory· Published Feb 13, 2023· Updated Jun 17, 2026
CVE-2022-4745
CVE-2022-4745
Description
The WP Customer Area WordPress plugin before 8.1.4 does not have CSRF checks when performing some actions such as chmod, mkdir and copy, which could allow attackers to make a logged-in admin perform them and create arbitrary folders, copy file for example.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- cpe:2.3:a:wp-customerarea:wp_customer_area:*:*:*:*:*:wordpress:*:*Range: <8.1.4
- Range: <8.1.4
- Range: 0
Patches
Vulnerability mechanics
References
1- wpscan.com/vulnerability/9703f42e-bdfe-4787-92c9-47963d9af425nvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.