PT-2022-24187 · WordPress · Awesome Support

Re-Alter

+1

·

Published

2022-09-21

·

Updated

2022-09-23

·

CVE-2022-38073

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Awesome Support plugin versions <= 6.0.7
Description The issue is related to a Multiple Authenticated Persistent Cross-Site Scripting (XSS) vulnerability. This vulnerability affects the Awesome Support plugin at WordPress, where users with a custom specific plugin role can exploit it.
Recommendations For Awesome Support plugin versions <= 6.0.7, update to a version greater than 6.0.7 to resolve the issue.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-38073
GHSA-QRQM-574X-Q7F2

Affected Products

Awesome Support