MEDIUM
WordPress Code Snippets Extended plugin <= 1.4.7 - Cross-Site Request Forgery (CSRF) vulnerability
Published May 17, 2022
5.4
MEDIUMCVSS 3.1
EPSS 0.40%
Description
Cross-Site Request Forgery (CSRF) vulnerability in Alexander Stokmann's Code Snippets Extended plugin <= 1.4.7 on WordPress allows an attacker to delete or to turn on/off snippets.
Affected products
-
Affected
- ≥ <= 1.4.7, ≤ 1.4.7
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Alexander Stokmann | Code Snippets Extended (WordPress plugin) | unknown | Affected
|
- ≤ 1.4.7
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
Deactivate and delete. No patched version is available. No reply from the vendor.
Weaknesses (1)
References (3)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-33773 Advisory
- https://patchstack.com/database/vulnerability/code-snippets-extended/wordpress-code-snippets-extended-plugin-1-4-7-cross-site-request-forgery-csrf-vulnerability x_refsource_CONFIRMThird Party Advisory
- https://wordpress.org/plugins/code-snippets-extended/#developers x_refsource_CONFIRMVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-33773 | Advisory | |
| https://patchstack.com/database/vulnerability/code-snippets-extended/wordpress-code-snippets-extended-plugin-1-4-7-cross-site-request-forgery-csrf-vulnerability | x_refsource_CONFIRMThird Party Advisory | |
| https://wordpress.org/plugins/code-snippets-extended/#developers | x_refsource_CONFIRMVendor Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Patchstack
Published May 17, 2022
Updated Apr 28, 2026
Reserved Apr 18, 2022
Link CVE-2022-29435
CISA Vulnrichment
Updated Feb 20, 2025
Red Hat
No data
GitHub
No data