CVE-2022-1442
HIGH NUCLEIMetForm < 2.1.3 - Unauthenticated Sensitive Information Disclosure in action.php
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2022-1442. PoCs published by RandomRobbieBF. A Nuclei detection template is also available.
AI-analyzed exploit summary This PoC exploits an improper access control vulnerability in WordPress Plugin Metform <= 2.1.3, allowing unauthenticated attackers to disclose sensitive API keys and secrets via REST API endpoints. The script automates the extraction of form data containing third-party API credentials.
Description
The Metform WordPress plugin is vulnerable to sensitive information disclosure due to improper access control in the ~/core/forms/action.php file which can be exploited by an unauthenticated attacker to view all API keys and secrets of integrated third-party APIs like that of PayPal, Stripe, Mailchimp, Hubspot, HelpScout, reCAPTCHA and many more, in versions up to and including 2.1.3.
Exploits (1)
This PoC exploits an improper access control vulnerability in WordPress Plugin Metform <= 2.1.3, allowing unauthenticated attackers to disclose sensitive API keys and secrets via REST API endpoints. The script automates the extraction of form data containing third-party API credentials.
Nuclei Templates (1)
References (3)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N