CVE-2022-1208
Ultimate Member <= 2.3.2 - Stored Cross-Site Scripting
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
The Ultimate Member plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Biography field featured on individual user profile pages due to insufficient input sanitization and output escaping that allows users to encode malicious web scripts with HTML encoding that is reflected back on the page. This affects versions up to, and including, 2.3.2. Please note this issue was only partially fixed in version 2.3.2.
El plugin Ultimate Member para WordPress es vulnerable a un ataque de tipo Cross-Site Scripting Almacenado por medio del campo Biography que aparece en las páginas de perfil de usuarios individuales debido a un saneo insuficiente de la entrada y escape de la salida que permite a usuarios codificar scripts web maliciosos con codificación HTML que es reflejada en la página. Esto afecta a versiones hasta la 2.3.2 incluyéndola. Tenga en cuenta que este problema fue parcialmente corregido en versión 2.3.2 y posteriormente fue parcheado por completo en versión 2.3.3
CVSS Scores
SSVC
- Decision:-
Timeline
- 2022-03-21 CVE Published
- 2022-04-01 CVE Reserved
- 2024-08-02 CVE Updated
- 2024-08-02 First Exploit
- 2024-09-04 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
References (4)
URL | Date | SRC |
---|---|---|
https://github.com/H4de5-7/vulnerabilities/blob/main/Ultimate%20Member%20%3C%3D%202.3.1%20-%20Stored%20Cross-Site%20Scripting.md | 2024-08-02 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Ultimatemember Search vendor "Ultimatemember" | Ultimate Member Search vendor "Ultimatemember" for product "Ultimate Member" | <= 2.3.2 Search vendor "Ultimatemember" for product "Ultimate Member" and version " <= 2.3.2" | wordpress |
Affected
|