CVE-2022-43468

External initialization of trusted variables or data stores vulnerability exists in WordPress Popular Posts 6.0.5 and earlier, therefore the vulnerable product accepts untrusted external inputs to update certain internal variables. As a result, the number of views for an article may be manipulated through a crafted input.
Configurations

Configuration 1 (hide)

cpe:2.3:a:wordpress_popular_posts_project:wordpress_popular_posts:*:*:*:*:*:wordpress:*:*

History

23 Apr 2025, 19:16

Type Values Removed Values Added
References (MISC) https://jvn.jp/en/jp/JVN13927745/index.html - Third Party Advisory () https://jvn.jp/en/jp/JVN13927745/index.html - Third Party Advisory
References (MISC) https://wordpress.org/plugins/wordpress-popular-posts/ - Product () https://wordpress.org/plugins/wordpress-popular-posts/ - Product
References (MISC) https://github.com/cabrerahector/wordpress-popular-posts/ - Third Party Advisory () https://github.com/cabrerahector/wordpress-popular-posts/ - Third Party Advisory

Information

Published : 2022-12-07 04:15

Updated : 2025-04-23 19:16


NVD link : CVE-2022-43468

Mitre link : CVE-2022-43468


JSON object : View

Products Affected

wordpress_popular_posts_project

  • wordpress_popular_posts
CWE
CWE-665

Improper Initialization