CVE Database /
CVE-2022-29489
CVE
CVE-2022-29489 — Sucuri Security – Auditing, Malware Scanner and Security Hardening [sucuri-scanner] < 1.8.34
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2022-29489
|
Sucuri Security – Auditing, Malware Scanner and Security Hardening [sucuri-scanner] < 1.8.34 |
Cross-Site Request Forgery (CSRF) |
Unknown
|
< 1.8.34
|
1.8.34 |
2022-09-14 |
—
|
CVE-2022-29489
The Sucuri Security plugin for WordPress versions up to 1.8.33 contains a Cross-Site Request Forgery vulnerability stemming from inadequate nonce validation across multiple hooks. An unauthenticated attacker could exploit this flaw to create fraudulent log entries for theme and plugin modifications or deletions if they can deceive a site administrator into clicking a malicious link. The vulnerability was addressed in version 1.8.34.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings