CVE-2022-3096
WP Total Hacks <= 4.7.2 - Subscriber+ Arbitrary Options Update to Stored XSS
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
The WP Total Hacks WordPress plugin through 4.7.2 does not prevent low privilege users from modifying the plugin's settings. This could allow users such as subscribers to perform Stored Cross-Site Scripting attacks against other users, like administrators, due to the lack of sanitisation and escaping as well.
El complemento de WordPress WP Total Hacks hasta 4.7.2 no impide que los usuarios con privilegios bajos modifiquen la configuración del complemento. Esto podría permitir a usuarios como suscriptores realizar ataques de Stored Cross-Site Scripting contra otros usuarios, como administradores, debido a la falta de sanitización y también de escape.
The WP Total Hacks plugin for WordPress is vulnerable to stored Plugin Options Update and Cross-Site Scripting in versions up to, and including, 4.7.2 This allows authenticated attackers with subscriber-level permissions the ability to embed JavaScript which will be executed in the browser of anyone who logs into the admin area, even if unfiltered_html is disallowed.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2022-09-02 CVE Reserved
- 2022-10-10 CVE Published
- 2024-08-03 CVE Updated
- 2024-08-03 First Exploit
- 2024-12-17 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- CWE-862: Missing Authorization
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|---|---|
https://wpscan.com/vulnerability/46996537-a874-4b2e-9cd7-7d0832f9704d | 2024-08-03 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Wp Total Hacks Project Search vendor "Wp Total Hacks Project" | Wp Total Hacks Search vendor "Wp Total Hacks Project" for product "Wp Total Hacks" | <= 4.7.2 Search vendor "Wp Total Hacks Project" for product "Wp Total Hacks" and version " <= 4.7.2" | wordpress |
Affected
|