PT-2022-10569 · WordPress · Comment Guestbook Plugin

Asif Nawaz

+1

·

Published

2022-09-30

·

Updated

2022-10-04

·

CVE-2021-36830

CVSS v3.1

4.8

Medium

VectorAV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Comment Guestbook plugin versions <= 0.8.0 at WordPress.
Description The issue is an Authenticated Stored Cross-Site Scripting (XSS) vulnerability. This means that an attacker, who has admin or higher privileges, can inject malicious scripts into the website, which will be executed by other users' browsers. The estimated number of potentially affected devices worldwide is not available. There is no information about real-world incidents where this issue was exploited.
Recommendations For Comment Guestbook plugin versions <= 0.8.0, update to a version higher than 0.8.0 to resolve the issue. As a temporary workaround, consider disabling the Comment Guestbook plugin until a patch is available. Restrict access to the plugin's functionality to minimize the risk of exploitation.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2021-36830

Affected Products

Comment Guestbook Plugin