Entreprise d'experts en Sécurité Informatique : Audits et conseils en cybersécurité
Entreprise française de cybersécurité depuis 2004
☎ 03 60 47 09 81 - info@securiteinfo.com


CVE-2022-1761

Description

The Peter’s Collaboration E-mails WordPress plugin through 2.2.0 is vulnerable to CSRF due to missing nonce checks. This allows the change of its settings, which can be used to lower the required user level, change texts, the used email address and more.

POC

Reference

- https://wpscan.com/vulnerability/31b413e1-d4b5-463e-9910-37876881c062

Github

- https://github.com/20142995/nuclei-templates

- https://github.com/ARPSyndicate/cvemon