PT-2022-17435 · WordPress · Simple Payment Donations & Subscriptions

Rafshanzani Suhada

·

Published

2022-09-05

·

Updated

2022-09-08

·

CVE-2022-2565

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Simple Payment Donations & Subscriptions WordPress plugin versions prior to 4.2.1
Description The issue is related to the plugin not sanitizing and escaping user input in its forms, which could allow unauthenticated attackers to perform Cross-Site Scripting attacks against admins.
Recommendations For versions prior to 4.2.1, update to version 4.2.1 or later to resolve the issue. As a temporary workaround, consider restricting access to the plugin's forms to minimize the risk of exploitation.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2022-2565

Affected Products

Simple Payment Donations & Subscriptions