CVE-2022-1709

MEDIUM

Throws SPAM Away < 3.3.1 - Cross-Site Request Forgery in Comment Deletion

Title source: llm
STIX 2.1

Description

The Throws SPAM Away WordPress plugin before 3.3.1 does not have CSRF checks in place when deleting comments (either all, spam, or pending), allowing attackers to make a logged in admin delete comments via a CSRF attack

References (1)

Core 1
Core References
Exploit, Third Party Advisory x_refsource_misc
https://wpscan.com/vulnerability/ac290535-d9ec-459a-abc3-27cd78eb54fc

Scores

CVSS v3 4.3
EPSS 0.0041
EPSS Percentile 33.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

Details

CWE
CWE-352
Status published
Products (1)
gti/throws_spam_away < 3.3.1
Published Jun 08, 2022
Tracked Since Feb 18, 2026