Sploitus

CVE-2022-3907

1 known exploit for CVE-2022-3907

The Clerk WordPress plugin before 4.0.0 is affected by time-based attacks in the validation function for all API requests due to the usage of comparison operators to verify API keys against the ones stored in the site options.

Affected products
Clerk
Clerk.io
< 4.0.0
Fix
Available
CVSS 3.1
7.5 HIGH
EPSS
0.9% (57th percentile)
Weakness
CWE-203
NVD status
Modified
Published
2022-12-05
CVE-2022-3907 at NVD
Authoritative description, scoring and affected products

1 known exploit for CVE-2022-3907

Proof-of-concept code and exploit modules indexed by Sploitus