CVE-2022-4488

The Widgets on Pages WordPress plugin before 1.8.0 does not validate and escape its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:widgets_on_pages_project:widgets_on_pages:*:*:*:*:*:wordpress:*:*

History

07 Nov 2023, 03:57

Type Values Removed Values Added
CWE CWE-79

05 Jul 2023, 14:15

Type Values Removed Values Added
Summary The Widgets on Pages WordPress plugin through 1.6.0 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins. The Widgets on Pages WordPress plugin before 1.8.0 does not validate and escape its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.

Information

Published : 2023-02-13 15:15

Updated : 2024-02-28 19:51


NVD link : CVE-2022-4488

Mitre link : CVE-2022-4488

CVE.ORG link : CVE-2022-4488


JSON object : View

Products Affected

widgets_on_pages_project

  • widgets_on_pages
CWE

No CWE.