CVE Vulnerabilities

CVE-2022-4004

Published: Dec 12, 2022 | Modified: Nov 07, 2023
CVSS 3.x
4.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

The Donation Button WordPress plugin through 4.0.0 does not properly check for privileges and nonce tokens in its donation_button_twilio_send_test_sms AJAX action, which may allow any users with an account on the affected site, like subscribers, to use the plugins Twilio integration to send SMSes to arbitrary phone numbers.

Affected Software

Name Vendor Start Version End Version
Donation_button Donation_button_project * 4.0.0 (including)

References