The Clerk WordPress plugin before 4.0.0 is affected by time-based attacks in the validation function for all API requests due to the usage of comparison operators to verify API keys against the ones stored in the site options.
Metrics
Affected Vendors & Products
References
History
Wed, 23 Apr 2025 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|

Status: PUBLISHED
Assigner: WPScan
Published: 2022-12-05T16:50:39.205Z
Updated: 2025-04-23T15:02:05.806Z
Reserved: 2022-11-09T02:55:10.063Z
Link: CVE-2022-3907

Updated: 2024-08-03T01:20:58.790Z

Status : Modified
Published: 2022-12-05T17:15:10.593
Modified: 2025-04-23T15:15:50.907
Link: CVE-2022-3907

No data.