Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2022-4974— Freemius SDK <= 2.4.2 - Missing Authorization Checks

Quick assessment

Affected
dashlabsltd YASR – Yet Another Star Rating Plugin for WordPress
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

WordPress和WordPress plugin都是WordPress基金会的产品。WordPress是一套使用PHP语言开发的博客平台。该平台支持在PHP和MySQL的服务器上架设个人博客网站。WordPress plugin是一个应用插件。 WordPress plugin Freemius SDK 2.4.2版本及之前版本存在安全漏洞,该漏洞源于缺少对 _get_debug_log、_get_db_option 和 _set_db_option 函数的能力检查和随机数保护,导致容易受到跨站点请求

CVSS 6.3 · Medium EPSS 0.44% · P37
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2022-4974

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Freemius SDK <= 2.4.2 - Missing Authorization Checks
Source: CVE Program / CVE List V5
Vulnerability Description
The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions in versions up to, and including 2.4.2. Any WordPress plugin or theme running a version of Freemius less than 2.4.3 is vulnerable.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Source: CVE Program / CVE List V5
Vulnerability Type
授权机制缺失
Source: CVE Program / CVE List V5
Vulnerability Title
WordPress plugin Freemius SDK 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
WordPress和WordPress plugin都是WordPress基金会的产品。WordPress是一套使用PHP语言开发的博客平台。该平台支持在PHP和MySQL的服务器上架设个人博客网站。WordPress plugin是一个应用插件。 WordPress plugin Freemius SDK 2.4.2版本及之前版本存在安全漏洞,该漏洞源于缺少对 _get_debug_log、_get_db_option 和 _set_db_option 函数的能力检查和随机数保护,导致容易受到跨站点请求
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
paretodigital YASR – Yet Another Star Rating Plugin for WordPress * ~ 2.0.2 -
nicheaddons Events Addon for Elementor * ~ 1.9.8 -
dots Fraud Prevention For WooCommerce and EDD * ~ 2.1.0 -
wpengine Gutenberg Blocks – ACF Blocks Suite * ~ 2.6.8 -
bouncingsprout Ultimeter * ~ 2.7.6 -
toddhalfpenny Past Events Extension * -
pootlepress Pootle Pagebuilder – WordPress Page builder * ~ 5.7.1 -
powerfulwp Local Delivery Drivers for WooCommerce * ~ 1.8.5 -
kkikuchi1220 Ultimate Gutenberg – Custom Block Templates * -
josevega WP Required Taxonomies – Categories and Tags Mandatory * ~ 1.1.8 -
pmbaldha Featured Products First for WooCommerce – A Extension of WooCommerce (WooCommerce Addon Plugin) * -
sslzen SSL Certificate – Free SSL, HTTPS by SSL Zen * ~ 4.0.4 -
wisersteps Streak CRM For Gmail For Contact Form 7 – WordPress Plugin * ~ 1.0.9 -
wpdevpowers WordPress Dev Powers – ACF Color Coded Field Types Plugin * -
benmoreassynt DancePress (TRWA) * ~ 3.1.2 -
dots Product Size Charts Plugin for WooCommerce * ~ 2.2.3 -
tribalnerd Wp My Admin Bar * -
setka A no-code page builder for beautiful performance-based content * ~ 2.1.17 -
mikebels LocalSEOMap * -
cromer12 Easy Prayer * -
rafalosinski AdFoxly – Ad Manager, AdSense Ads & Ads.txt * ~ 1.8.4 -
stevehenty WP Get Personal * -
theafricanboss/ Checkout with Cash App on EDD * -
usmanaliqureshi Server Info * -
themelocation Custom WooCommerce Checkout Fields Editor * ~ 1.2.6 -
krsp KRSP Frontend File Uploader * -
bplugins Panorama Viewer- Best Plugin to Display Panoramic Images/Videos * ~ 1.0.8 -
janwyl Bulk Attachment Download * ~ 1.3.5 -
majick AutoSave Net * -
premmerce Premmerce Wholesale Pricing for WooCommerce * ~ 1.1.8 -

II. Public POCs for CVE-2022-4974

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2022-4974

登录查看更多情报信息。

Vendor Advisories for CVE-2022-4974 (2)

Security Blog Posts for CVE-2022-4974 (1)

Other References for CVE-2022-4974 (2)

Other References for CVE-2022-4974 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2022-4974

No comments yet


Leave a comment