PT-2022-18641 · WordPress · Kb Support

Thiennv

·

Published

2022-04-15

·

Updated

2024-09-16

·

CVE-2022-27852

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions KB Support (WordPress plugin) versions 1.5.5 and earlier
Description The issue concerns multiple unauthenticated stored Cross-Site Scripting (XSS) vulnerabilities. Cross-Site Scripting (XSS) is a type of security vulnerability that allows an attacker to inject malicious scripts into a website, potentially leading to unauthorized access or control of user sessions.
Recommendations For KB Support (WordPress plugin) versions 1.5.5 and earlier, update to a version later than 1.5.5 to resolve the issue.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2022-27852

Affected Products

Kb Support