PT-2022-20738 · WordPress · Wordfence Security – Firewall & Malware Scan
Ori Gabriel
·
Published
2022-09-23
·
Updated
2024-01-11
·
CVE-2022-3144
CVSS v3.1
4.8
Medium
| Vector | AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Wordfence Security – Firewall & Malware Scan plugin for WordPress versions up to and including 7.6.0
Description
The issue allows authenticated users with administrative privileges to inject malicious web scripts into a setting on the options page due to insufficient escaping on the stored value. This makes it possible for the malicious scripts to execute whenever a user accesses a page displaying the affected setting on sites running a vulnerable version.
Recommendations
For versions up to and including 7.6.0, update to a version later than 7.6.0 to resolve the issue.
As a temporary workaround, consider restricting access to the options page to minimize the risk of exploitation.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Wordfence Security – Firewall & Malware Scan