CVE-2022-4604

Source
https://nvd.nist.gov/vuln/detail/CVE-2022-4604
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2022-4604.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2022-4604
Published
2022-12-18T11:15:11.170Z
Modified
2025-11-14T13:53:54.846252Z
Severity
  • 8.8 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

A vulnerability classified as problematic was found in wp-english-wp-admin Plugin up to 1.5.1. Affected by this vulnerability is the function register_endpoints of the file english-wp-admin.php. The manipulation leads to cross-site request forgery. The attack can be launched remotely. Upgrading to version 1.5.2 is able to address this issue. The name of the patch is ad4ba171c974c65c3456e7c6228f59f40783b33d. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-216199.

References

Affected packages

Git / github.com/khromov/wp-english-wp-admin

Affected ranges

Type
GIT
Repo
https://github.com/khromov/wp-english-wp-admin
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Fixed

Affected versions

1.*

1.4
1.4.1
1.5.1
1.5.1.1