The FL3R FeelBox WordPress plugin through 8.1 does not have CSRF check when updating reseting moods which could allow attackers to make logged in admins perform such action via a CSRF attack and delete the lydl_posts & lydl_poststimestamp DB tables
Metrics
Affected Vendors & Products
References
History
Tue, 07 Oct 2025 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Armandofiore
Armandofiore fl3r Feelbox |
|
| Weaknesses | CWE-352 | |
| CPEs | cpe:2.3:a:armandofiore:fl3r_feelbox:*:*:*:*:*:wordpress:*:* | |
| Vendors & Products |
Fl3r Feelbox Project
Fl3r Feelbox Project fl3r Feelbox |
Armandofiore
Armandofiore fl3r Feelbox |
Thu, 27 Mar 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: WPScan
Published: 2023-01-30T20:31:44.026Z
Updated: 2025-03-27T19:44:35.223Z
Reserved: 2022-12-16T10:20:37.972Z
Link: CVE-2022-4553
Updated: 2024-08-03T01:41:45.636Z
Status : Analyzed
Published: 2023-01-30T21:15:11.197
Modified: 2025-10-07T15:35:42.573
Link: CVE-2022-4553
No data.