CVE-2022-1251

The Ask me WordPress theme before 6.8.4 does not perform nonce checks when processing POST requests to the Edit Profile page, allowing an attacker to trick a user to change their profile information by sending a crafted request.
References
Configurations

Configuration 1

cpe:2.3:a:inkthemes:ask_me:*:*:*:*:*:wordpress:*:*

Information

Published : 2022-08-22 03:15

Updated : 2022-08-23 06:44


NVD link : CVE-2022-1251

Mitre link : CVE-2022-1251

Products Affected
No products.
CWE