{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-05-07T08:36:16.422","vulnerabilities":[{"cve":{"id":"CVE-2018-1000507","sourceIdentifier":"cve@mitre.org","published":"2018-06-26T16:29:00.743","lastModified":"2024-11-21T03:40:04.450","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"WP User Groups version 2.0.0 contains a Cross ite Request Forgery (CSRF) vulnerability in Settings page that can result in allows anybody to modify user groups and types. This attack appear to be exploitable via Admin must click on link. This vulnerability appears to have been fixed in 2.1.1."},{"lang":"es","value":"WP User Groups 2.0.0 contiene una vulnerabilidad de Cross-Site Request Forgery (CSRF) en la página Settings que puede resultar en que cualquiera pueda modificar grupos y tipos de usuario. El ataque parece ser explotable mediante un administrador que abra un enlace. La vulnerabilidad parece haber sido solucionada en la versión 2.1.1."}],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-352"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:jjj:wp_user_groups:2.0.0:*:*:*:*:wordpress:*:*","matchCriteriaId":"270DECD8-4761-4B95-BED4-A106036C0AA5"}]}]}],"references":[{"url":"https://advisories.dxw.com/advisories/csrf-wp-user-groups/","source":"cve@mitre.org","tags":["Exploit","Third Party Advisory"]},{"url":"https://advisories.dxw.com/advisories/csrf-wp-user-groups/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Third Party Advisory"]}]}}]}