{"dataType":"CVE_RECORD","dataVersion":"5.1","cveMetadata":{"state":"PUBLISHED","cveId":"CVE-2022-43468","assignerOrgId":"ede6fdc4-6654-4307-a26d-3331c018e2ce","assignerShortName":"jpcert","dateUpdated":"2025-04-23T18:15:21.717Z","dateReserved":"2022-11-16T00:00:00.000Z","datePublished":"2022-12-07T00:00:00.000Z"},"containers":{"cna":{"providerMetadata":{"orgId":"ede6fdc4-6654-4307-a26d-3331c018e2ce","shortName":"jpcert","dateUpdated":"2022-12-07T00:00:00.000Z"},"descriptions":[{"lang":"en","value":"External initialization of trusted variables or data stores vulnerability exists in WordPress Popular Posts 6.0.5 and earlier, therefore the vulnerable product accepts untrusted external inputs to update certain internal variables. As a result, the number of views for an article may be manipulated through a crafted input."}],"affected":[{"vendor":"Hector Cabrera","product":"WordPress Popular Posts","versions":[{"version":"6.0.5 and earlier","status":"affected"}]}],"references":[{"url":"https://wordpress.org/plugins/wordpress-popular-posts/"},{"url":"https://github.com/cabrerahector/wordpress-popular-posts/"},{"url":"https://jvn.jp/en/jp/JVN13927745/index.html"}],"problemTypes":[{"descriptions":[{"type":"text","lang":"en","description":"External Initialization of Trusted Variables or Data Stores"}]}]},"adp":[{"providerMetadata":{"orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE","dateUpdated":"2024-08-03T13:32:59.916Z"},"title":"CVE Program Container","references":[{"url":"https://wordpress.org/plugins/wordpress-popular-posts/","tags":["x_transferred"]},{"url":"https://github.com/cabrerahector/wordpress-popular-posts/","tags":["x_transferred"]},{"url":"https://jvn.jp/en/jp/JVN13927745/index.html","tags":["x_transferred"]}]},{"problemTypes":[{"descriptions":[{"type":"CWE","cweId":"CWE-665","lang":"en","description":"CWE-665 Improper Initialization"}]}],"metrics":[{"cvssV3_1":{"scope":"UNCHANGED","version":"3.1","baseScore":7.5,"attackVector":"NETWORK","baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","integrityImpact":"HIGH","userInteraction":"NONE","attackComplexity":"LOW","availabilityImpact":"NONE","privilegesRequired":"NONE","confidentialityImpact":"NONE"}},{"other":{"type":"ssvc","content":{"timestamp":"2025-04-23T18:14:52.782920Z","id":"CVE-2022-43468","options":[{"Exploitation":"none"},{"Automatable":"yes"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2025-04-23T18:15:21.717Z"}}]}}