← back
CVE-2022-3024mediumCWE-352CWE-863

Simple Bitcoin Faucets <= 1.7.0 - Unauthorised AJAX Call to Stored XSS

13Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 5.4epss 0.3%
exploitation probability
0.3%top 81% of all CVEs
observed exploitation
nono source reports it
The Simple Bitcoin Faucets WordPress plugin through 1.7.0 does not have any authorisation and CSRF in an AJAX action, allowing any authenticated users, such as subscribers to call it and add/delete/edit Bonds. Furthermore, due to the lack of sanitisation and escaping, it could also lead to Stored Cross-Site Scripting issues
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N