The Pakistan Telecommunication Authority (PTA) has issued a Cyber Security Advisory highlighting a critical vulnerability in the WP Tools plugin for WordPress. Identified as CVE-2022-43453, the flaw allows a remote authenticated attacker to bypass security measures due to an authorization omission.
This vulnerability enables an attacker to exploit access controls through a carefully crafted request, raising significant cybersecurity concerns for users of the affected software. The PTA has urged users and administrators of WordPress sites to act promptly to address the threat by updating to the latest version of the plugin, which can be accessed through the WordPress Plugin Directory.