Back to Database
Status published
Medium
CVE-2022-36404
WordPress Simple SEO plugin <= 1.8.12 - Broken Access Control vulnerability
Vulnerability Description
Missing Authorization, Cross-Site Request Forgery (CSRF) vulnerability in David Cole Simple SEO (WordPress plugin) plugin <= 1.8.12 versions.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2022-36404
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Mika (Patchstack Alliance)
Affected Vendor
David Cole
View all reports →Affected Software
Simple SEO (WordPress plugin)
Vulnerable Versions:
Unknown
Timeline
Official Publish:
November 3rd, 2022
Last Modified:
April 28th, 2026
Added to House:
July 21st, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L
MITRE ATT&CK TTPs
T1190
Exploit Public-Facing Application
Initial Access
T1068
Exploitation for Privilege Escalation
Privilege Escalation
T1078
Valid Accounts
Persistence
T1531
Account Access Removal
Impact
T1566.002
Spearphishing Link
Initial Access
T1204.001
Malicious Link
Execution
T1098
Account Manipulation
Persistence
T1565.001
Stored Data Manipulation
Impact