CVE-2022-3506
Cross-site Scripting (XSS) - Stored in barrykooij/related-posts-for-wp
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
Cross-site Scripting (XSS) - Stored in GitHub repository barrykooij/related-posts-for-wp prior to 2.1.3.
Una vulnerabilidad de tipo Cross-site Scripting (XSS) - Almacenado en el repositorio de GitHub barrykooij/related-posts-for-wp versiones anteriores a 2.1.3
The Related Posts for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘heading_text’ parameter in versions up to, and including, 2.1.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Note, this vulnerability was independently found by two researchers.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2022-10-14 CVE Reserved
- 2022-10-14 CVE Published
- 2024-05-06 EPSS Updated
- 2024-08-03 CVE Updated
- 2024-08-03 First Exploit
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
References (2)
URL | Tag | Source |
---|
URL | Date | SRC |
---|---|---|
https://huntr.dev/bounties/08251542-88f6-4264-9074-a89984034828 | 2024-08-03 |
URL | Date | SRC |
---|---|---|
https://github.com/barrykooij/related-posts-for-wp/commit/37733398dd88863fc0bdb3d6d378598429fd0b81 | 2023-03-06 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Never5 Search vendor "Never5" | Related Posts Search vendor "Never5" for product "Related Posts" | < 2.1.3 Search vendor "Never5" for product "Related Posts" and version " < 2.1.3" | wordpress |
Affected
|