CVE-2022-1594 describes a Cross-Site Request Forgery (CSRF) vulnerability in the HC Custom WP-Admin URL WordPress plugin, affecting versions up to 1.4. This flaw allows an attacker to trick a logged-in administrator into unknowingly changing the WordPress login URL. The vulnerability has a CVSS score of 4.3 (MEDIUM), indicating a network-based attack with low complexity, requiring user interaction but resulting in only low integrity impact (changing the login URL). There is no evidence of active exploitation, and no public exploit code (Metasploit, Nuclei, ExploitDB) is available. Community discussion and media coverage for this CVE are extremely low, suggesting minimal public awareness or concern. The EPSS score is also very low, indicating a low probability of exploitation in the wild.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.4CPE matchmatch criteria | cpe:2.3:a:hc_custom_wp-admin_url_project:hc_custom_wp-admin_url:*:*:*:*:*:wordpress:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.