PT-2022-13782 · WordPress · Imdb Info Box

Fayçal Chena

·

Published

2022-05-30

·

Updated

2022-06-08

·

CVE-2022-1294

CVSS v3.1

4.8

Medium

VectorAV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions IMDB info box WordPress plugin versions through 2.0
Description The issue allows high-privileged users to perform Cross-Site Scripting attacks due to the lack of sanitization and escaping of some settings, even when the unfiltered html capability is disallowed.
Recommendations For IMDB info box WordPress plugin versions through 2.0, consider updating to a version that addresses this issue, as no specific workaround is provided for these versions. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-1294

Affected Products

Imdb Info Box