CVE-2022-4946

AccessPress Anonymous Post <= 2.8.4 - Authenticated (Contributor+) Arbitrary Redirect

2023-05-11 00:00
WPScanTeam

Strategic Overview

Status
Unpatched
Affected Version
<= 2.8.4
CVSS
4.3Medium
Weakness type
CWE-601 · URL Redirection to Untrusted Site ('Open Redirect')
CVE
CVE-2022-4946
View all Frontend Post WordPress Plugin – AccessPress Anonymous Post vulnerabilities

At a glance

CVE-2022-4946 is a medium-severity URL Redirection to Untrusted Site ('Open Redirect') vulnerability in the Frontend Post WordPress Plugin WordPress plugin, affecting versions <= 2.8.4. It carries a CVSS score of 4.3 (reachable over the network; low attack complexity). Exploitation requires an authenticated account at Contributor level or above. No fixed release has been reported yet; treat installations running this software as exposed. Disclosed May 2023, reported by WPScanTeam.

Vulnerability Overview

The AccessPress Anonymous Post plugin for WordPress is vulnerable to Arbitrary Redirect in versions up to, and including, 2.8.4. This is due to insufficient validation on one of the attributes for one of its shortcodes. This makes it possible for authenticated attackers, with contributor-level access, to redirect users to potentially malicious sites.

Technical Analysis

The vector marks this flaw as remotely reachable over the network, with low attack complexity — no special timing or configuration is needed, and no interaction from a victim user.

CWE-601: URL Redirection to Untrusted Site ('Open Redirect')

Reaching this weakness in Frontend Post WordPress Plugin <= 2.8.4 takes an account at Contributor level or above. An open redirect is a page that takes a destination from the request and sends the browser there without checking that the destination belongs to the site.

A link that starts on a trusted domain finishes on an attacker's, which is what makes phishing and consent-screen abuse credible to the person clicking it. No fixed build of this plugin is recorded for Frontend Post WordPress Plugin yet, so installs running <= 2.8.4 stay exposed until the vendor ships one.

Remediation

No known patch available. Please review the vulnerability's details in depth and employ mitigations based on your organization's risk tolerance. It may be best to uninstall the affected software and find a replacement.

How does WordSec protect against this?

An attacker needs Contributor access first, so the firewall sees the attempt as traffic from a logged-in account: WordSec's web application firewall inspects request payloads before WordPress loads them. No patched version is recorded yet, which is the case where a filtering layer matters most, because there is nothing to update to.

  • Firewall
  • Alerts

External References

Related records

Other vulnerabilities in Frontend Post WordPress Plugin – AccessPress Anonymous Post

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C