PT-2022-14964 · Linkedin · Company Updates Wordpress Plugin

Krishna Harsha Kondaveeti

+1

·

Published

2022-07-17

·

Updated

2022-07-18

·

CVE-2022-2148

CVSS v3.1

4.8

Medium

VectorAV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions The LinkedIn Company Updates WordPress plugin versions 1.5.3 and earlier
Description The issue allows high privilege users, such as admin, to perform cross-Site Scripting attacks due to the plugin not sanitising and escaping its settings. This is possible even when the unfiltered html capability is disallowed.
Recommendations For versions 1.5.3 and earlier, update to a version that properly sanitises and escapes its settings to prevent cross-Site Scripting attacks. As a temporary workaround, consider restricting the use of the plugin's settings by high privilege users until a patch is available.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-2148

Affected Products

Company Updates Wordpress Plugin