{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-06-21T04:44:05.284","vulnerabilities":[{"cve":{"id":"CVE-2022-43468","sourceIdentifier":"vultures@jpcert.or.jp","published":"2022-12-07T04:15:10.723","lastModified":"2026-06-17T05:06:36.843","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"External initialization of trusted variables or data stores vulnerability exists in WordPress Popular Posts 6.0.5 and earlier, therefore the vulnerable product accepts untrusted external inputs to update certain internal variables. As a result, the number of views for an article may be manipulated through a crafted input."},{"lang":"es","value":"Vulnerabilidad de inicialización externa de variables confiables o almacenes de datos existe en WordPress Popular Posts 6.0.5 y versiones anteriores, por lo tanto, el producto vulnerable acepta entradas externas que no son confiables para actualizar ciertas variables internas. Como resultado, el número de vistas de un artículo puede manipularse mediante una entrada manipulada."}],"affected":[{"source":"vultures@jpcert.or.jp","affectedData":[{"vendor":"Hector Cabrera","product":"WordPress Popular Posts","versions":[{"version":"6.0.5 and earlier","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":3.6},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-04-23T18:14:52.782920Z","id":"CVE-2022-43468","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-665"}]},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-665"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:wordpress_popular_posts_project:wordpress_popular_posts:*:*:*:*:*:wordpress:*:*","versionEndIncluding":"6.0.5","matchCriteriaId":"185B79D8-4A8D-471F-8494-C4D017A3EBA1"}]}]}],"references":[{"url":"https://github.com/cabrerahector/wordpress-popular-posts/","source":"vultures@jpcert.or.jp","tags":["Third Party Advisory"]},{"url":"https://jvn.jp/en/jp/JVN13927745/index.html","source":"vultures@jpcert.or.jp","tags":["Third Party Advisory"]},{"url":"https://wordpress.org/plugins/wordpress-popular-posts/","source":"vultures@jpcert.or.jp","tags":["Product"]},{"url":"https://github.com/cabrerahector/wordpress-popular-posts/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]},{"url":"https://jvn.jp/en/jp/JVN13927745/index.html","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]},{"url":"https://wordpress.org/plugins/wordpress-popular-posts/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Product"]}]}}]}