CVE-2022-33994
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
The Gutenberg plugin through 13.7.3 for WordPress allows stored XSS by the Contributor role via an SVG document to the "Insert from URL" feature. NOTE: the XSS payload does not execute in the context of the WordPress instance's domain; however, analogous attempts by low-privileged users to reference SVG documents are blocked by some similar products, and this behavioral difference might have security relevance to some WordPress site administrators.
El plugin Gutenberg versiones hasta 13.7.3 para WordPress, permite un ataque de tipo XSS almacenado por el rol de Colaborador por medio de un documento SVG a la funcionalidad "Insert from URL". NOTA: la carga útil de tipo XSS no es ejecutada en el contexto del dominio de la instancia de WordPress; sin embargo, los intentos análogos de usuarios poco privilegiados de hacer referencia a documentos SVG son bloqueados por algunos productos similares, y esta diferencia de comportamiento podría tener relevancia de seguridad para algunos administradores de sitios de WordPress
CVSS Scores
SSVC
- Decision:-
Timeline
- 2022-06-19 CVE Reserved
- 2022-07-30 CVE Published
- 2024-02-20 EPSS Updated
- 2024-08-03 CVE Updated
- 2024-08-03 First Exploit
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
https://blog.jitendrapatro.me/cve-2022-33994-stored-xss-in-wordpress | Third Party Advisory |
URL | Date | SRC |
---|---|---|
https://patchstack.com/articles/patchstack-weekly-svg-xss-reported-in-gutenberg | 2024-08-03 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Gutenberg Project Search vendor "Gutenberg Project" | Gutenberg Search vendor "Gutenberg Project" for product "Gutenberg" | <= 13.7.3 Search vendor "Gutenberg Project" for product "Gutenberg" and version " <= 13.7.3" | wordpress |
Affected
|