PT-2022-19583 · WordPress · Wp-Useronline

Juampa Rodríguez

·

Published

2022-09-06

·

Updated

2023-11-02

·

CVE-2022-2941

CVSS v3.1

5.5

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions WP-UserOnline plugin for WordPress versions up to, and including 2.88.0
Description The issue is due to the lack of proper sanitization and escaping of user input in the "Naming Conventions" section, allowing authenticated attackers with administrative privileges to inject JavaScript code. This affects multi-site installations and installations where unfiltered html has been disabled.
Recommendations For versions up to, and including 2.88.0, update to a version that properly sanitizes user input in the "Naming Conventions" section to prevent JavaScript code injection. As a temporary workaround, consider restricting access to the "Naming Conventions" section for users with administrative privileges until a patch is available.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2022-2941

Affected Products

Wp-Useronline