PT-2022-19618 · Cloudways · Cloudways Breeze

Dave Jong

·

Published

2022-05-02

·

Updated

2022-05-09

·

CVE-2022-29444

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions Cloudways Breeze plugin versions <= 2.0.2
Description The issue allows users with a subscriber or higher user role to execute any of the wp ajax * actions in the class Breeze Configuration. This includes the ability to change any of the plugin's settings, including the CDN setting, which could be further used for a Cross-Site Scripting (XSS) attack.
Recommendations For Cloudways Breeze plugin versions <= 2.0.2, update to a version higher than 2.0.2 to resolve the issue. As a temporary workaround, consider restricting access to the Breeze Configuration class and its associated wp ajax * actions to prevent unauthorized changes to the plugin's settings. Restrict access to the CDN setting to minimize the risk of exploitation.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-29444

Affected Products

Cloudways Breeze