CVE-2022-1749: Wpmk AJAX Finder Project Wpmk AJAX Finder
High severity, CVSS 8.8. EPSS: 0.8% chance of exploitation in the next 30 days.
The WPMK Ajax Finder WordPress plugin is vulnerable to Cross-Site Request Forgery via the createplugin_atf_admin_setting_page() function found in the ~/inc/config/create-plugin-config.php file due to a missing nonce check which allows attackers to inject arbitrary web scripts, in versions up to and including 1.0.1.
Affected products
- Wpmk AJAX Finder Project Wpmk AJAX Finder: up to and including 1.0.1
Published 2022-06-13. Last modified 2026-06-17.