PT-2022-19589 · WordPress · Ravpage
Nguyen Anh Tien
+1
·
Published
2022-04-28
·
Updated
2022-05-04
·
CVE-2022-29415
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Ravpage plugin versions <= 2.16
Description
The issue is an Unauthenticated Reflected Cross-Site Scripting (XSS) vulnerability. This means that an attacker can inject malicious scripts into a website without needing to authenticate, potentially affecting users who visit the site. The vulnerability is present in the Ravpage plugin used with WordPress.
Recommendations
For Ravpage plugin versions <= 2.16, update to a version higher than 2.16 to resolve the issue.
At the moment, there is no information about other specific fixes for this vulnerability.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ravpage