CVE-2022-3907

HIGH

Clerk WordPress Plugin < 4.0.0 - Timing Attack via API Key Validation

Title source: llm
STIX 2.1

Description

The Clerk WordPress plugin before 4.0.0 is affected by time-based attacks in the validation function for all API requests due to the usage of comparison operators to verify API keys against the ones stored in the site options.

References (1)

Core 1
Core References
Exploit, Third Party Advisory exploit vdb-entry technical-description
https://wpscan.com/vulnerability/7920c1c1-709d-4b1f-ac08-f0a02ddb329c

Scores

CVSS v3 7.5
EPSS 0.0088
EPSS Percentile 54.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-203
Status published
Products (2)
clerk/clerk.io < 4.0.0
clerk.io/clerk.io < 4.0.0
Published Dec 05, 2022
Tracked Since Feb 18, 2026