CVE-2022-1895 Information

Description

The underConstruction WordPress plugin before 1.20 does not have CSRF check in place when deactivating the construction mode which could allow attackers to make a logged in admin perform such action via a CSRF attack

Reference

https://wpscan.com/vulnerability/bd9ef7e0-ebbb-4b91-8c58-265218a3c536

Share on: