PT-2022-21943 · WordPress · Fontmeister

Nguyen Anh Tien

+1

·

Published

2022-10-11

·

Updated

2022-10-13

·

CVE-2022-33978

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions FontMeister plugin versions <= 1.08 at WordPress.
Description The issue is a Reflected Cross-Site Scripting (XSS) vulnerability. This means an attacker can inject malicious scripts into a website, potentially stealing user data or taking control of the user's session.
Recommendations For FontMeister plugin versions <= 1.08, update to a version greater than 1.08 to resolve the issue.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2022-33978

Affected Products

Fontmeister