CVE Feed

    Dashboard / CVE / CVE-2022-4265

    CVE-2022-4265

    The Replyable WordPress plugin before 2.2.10 does not validate the class name submitted by the request when instantiating an object in the prompt_dismiss_notice action and also lacks CSRF check in the related action. This could allow any authenticated users, such as subscriber to perform Object Injection attacks. The attack could also be done via a CSRF vector against any authenticated user

    Published:Mar 6, 2023
    Last Modified:Mar 6, 2025
    EPS:Mar 6, 2023
    EPSS Score:0.00108
    CVSS Score:8.8

    Affected Products

    Vendor
    Gopostmatic
    Product
    Replyable

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High