CVE-2022-1717
Custom Share Buttons with Floating Sidebar < 4.2 - Admin+ Stored XSS
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
The Custom Share Buttons with Floating Sidebar WordPress plugin before 4.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks when the unfiltered_html capability is disallowed
El plugin Custom Share Buttons with Floating Sidebar de WordPress versiones anteriores a 4.2, no sanea ni escapa de algunas de sus configuraciones, lo que podría permitir a usuarios muy privilegiados, como los administradores, llevar a cabo ataques de tipo Cross-Site Scripting Almacenado cuando la capacidad unfiltered_html no está permitida
The Custom Share Buttons with Floating Sidebar plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 4.1 via several parameters. This makes it possible for authenticated attackers to inject arbitrary web scripts that may execute when a victim accesses a page containing the malicious payload.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2022-05-14 CVE Reserved
- 2022-05-18 CVE Published
- 2024-01-11 EPSS Updated
- 2024-08-03 CVE Updated
- 2024-08-03 First Exploit
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|---|---|
https://wpscan.com/vulnerability/79a532e9-bc6e-4722-8d67-9c15720d06a6 | 2024-08-03 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Wp-experts Search vendor "Wp-experts" | Custom Share Buttons With Floating Sidebar Search vendor "Wp-experts" for product "Custom Share Buttons With Floating Sidebar" | < 4.2 Search vendor "Wp-experts" for product "Custom Share Buttons With Floating Sidebar" and version " < 4.2" | wordpress |
Affected
|