PT-2022-16328 · WordPress · Inspiro Pro

Fort3

+1

·

Published

2022-07-26

·

Updated

2022-08-12

·

CVE-2022-2391

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Inspiro PRO WordPress plugin (affected versions not specified)
Description The issue allows users with privileges as low as Contributor to inject JavaScript into the portfolio slider description due to a lack of sanitization. This can lead to stored XSS attacks.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

XSS

Weakness Enumeration

Related Identifiers

CVE-2022-2391

Affected Products

Inspiro Pro