CVE-2022-3880

MEDIUM

antihacker < 4.20 - Authenticated Plugin Installation via AJAX Action

Title source: llm
STIX 2.1

Description

The Disable Json API, Login Lockdown, XMLRPC, Pingback, Stop User Enumeration Anti Hacker Scan WordPress plugin before 4.20 does not have proper authorisation and CSRF in an AJAX action, allowing any authenticated users, such as subscriber to call it and install and activate arbitrary plugins from wordpress.org

References (1)

Core 1
Core References
Exploit, Third Party Advisory exploit vdb-entry technical-description
https://wpscan.com/vulnerability/24743c72-310f-41e9-aac9-e05b2bb1a14e

Scores

CVSS v3 6.5
EPSS 0.0034
EPSS Percentile 25.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-352 CWE-863
Status published
Products (1)
antihacker_project/antihacker < 4.20
Published Dec 12, 2022
Tracked Since Feb 18, 2026