PT-2022-19610 · WordPress · Code Snippets Extended
Bee-K
+2
·
Published
2022-05-17
·
Updated
2022-05-25
·
CVE-2022-29436
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Code Snippets Extended plugin versions 1.4.7 and earlier
Description
The issue is related to a Persistent Cross-Site Scripting (XSS) vulnerability. It can be exploited via Cross-Site Request Forgery (CSRF) and involves vulnerable parameters
title and snippet code.Recommendations
For Code Snippets Extended plugin versions 1.4.7 and earlier, update to a version later than 1.4.7 to resolve the issue. As a temporary workaround, consider restricting access to the plugin's functionality to minimize the risk of exploitation. Avoid using the parameters
title and snippet code in the affected plugin until the issue is resolved.Fix
XSS
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Code Snippets Extended