CVE-2022-41990
WordPress 3D Tag Cloud Plugin <= 3.8 is vulnerable to Cross Site Request Forgery (CSRF)
CVSS Score
7.1
EPSS Score
0.0%
EPSS Percentile
0th
Cross-Site Request Forgery (CSRF) vulnerability in Vinoj Cardoza 3D Tag Cloud allows Stored XSS.This issue affects 3D Tag Cloud: from n/a through 3.8.
| CWE | CWE-352 |
| Vendor | vinoj cardoza |
| Product | 3d tag cloud |
| Published | Jan 17, 2024 |
| Last Updated | Apr 28, 2026 |
Stay Ahead of the Next One
Get instant alerts for vinoj cardoza 3d tag cloud
Be the first to know when new high vulnerabilities affecting vinoj cardoza 3d tag cloud are published — delivered to Slack, Telegram or Discord.
Get Free Alerts →
Free · No credit card · 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Changed
Confidentiality
Low
Integrity
Low
Availability
Low
Affected Versions
Vinoj Cardoza / 3D Tag Cloud
n/a ≤ 3.8
References
Credits
István Márton (Patchstack Alliance)