Beveiligingsadvies

CVE-2022-1442

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2022-05-10 19:30:12
Laatst bijgewerkt 2026-04-08 16:33:14
Toegewezen door Wordfence
CVSS-score 7.5
Status PUBLISHED

Beschrijving

The Metform WordPress plugin is vulnerable to sensitive information disclosure due to improper access control in the ~/core/forms/action.php file which can be exploited by an unauthenticated attacker to view all API keys and secrets of integrated third-party APIs like that of PayPal, Stripe, Mailchimp, Hubspot, HelpScout, reCAPTCHA and many more, in versions up to and including 2.1.3.