PT-2022-16590 · WordPress · Visual Composer Website Builder

Zhouyuan Yang

·

Published

2022-09-06

·

Updated

2022-09-12

·

CVE-2022-2430

CVSS v3.1

6.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Visual Composer Website Builder plugin for WordPress versions up to and including 45.0
Description The issue arises from insufficient input sanitization and output escaping in the 'Text Block' feature, allowing authenticated attackers with access to the visual composer editor to inject arbitrary web scripts in pages. These scripts will execute whenever a user accesses an injected page.
Recommendations For versions up to and including 45.0, update to a version that addresses the insufficient input sanitization and output escaping in the 'Text Block' feature to prevent stored cross-site scripting attacks.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2022-2430

Affected Products

Visual Composer Website Builder