Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
5.3

CVE-2022-46846: WP OnlineSupport Plugin Allows Unauthorized Access to Posts

CVE-2022-46846 · published 1 year ago
Summary

The WP OnlineSupport plugin has a security issue that allows unauthorized users to access posts they shouldn't be able to see. This affects the Trending/Popular Post Slider and Widget plugin, and users should update to the latest version to fix it. If not patched, an attacker could gain access to sensitive information.

Original advisory text
Missing Authorization vulnerability in WP OnlineSupport, Essential Plugin Trending/Popular Post Slider and Widget allows Exploiting Incorrectly Configured Access Control Security Levels.This issue ...
Missing Authorization vulnerability in WP OnlineSupport, Essential Plugin Trending/Popular Post Slider and Widget allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Trending/Popular Post Slider and Widget: from n/a through 1.5.7.
Severity
5.3 Medium
CVSS 3.1: 5.3 (NVD)
Exploitation
EPSS <1%
Type
CWE-862Missing Authorization
Timeline
Published13 Dec 2024
Updated15 Aug 2026
First seen7 Mar 2026
Sources
Monitor software like this
Free during beta