PT-2022-15652 · WordPress · Simple Quotation Wordpress Plugin

Abhishek Bhoir

·

Published

2022-03-14

·

Updated

2023-07-04

·

CVE-2022-22734

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions The Simple Quotation WordPress plugin versions 1.3.2 and earlier
Description The issue is related to the lack of CSRF check when creating or editing a quote and the failure to sanitise and escape quotes. This allows an attacker to make a logged-in admin create or edit arbitrary quotes and put Cross-Site Scripting payloads in them.
Recommendations For versions 1.3.2 and earlier, update to a version that includes a CSRF check and proper sanitization and escaping of quotes to prevent Cross-Site Scripting attacks. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Encoding or Escaping of Output

Weakness Enumeration

Related Identifiers

CVE-2022-22734

Affected Products

Simple Quotation Wordpress Plugin