← Volver a CVEs
CVE-2022-4973
MEDIUM4.9
Descripcion
WordPress Core, in versions up to 6.0.2, is vulnerable to Authenticated Stored Cross-Site Scripting that can be exploited by users with access to the WordPress post and page editor, typically consisting of Authors, Contributors, and Editors making it possible to inject arbitrary web scripts into posts and pages that execute if the the_meta(); function is called on that page.
Detalles CVE
Puntuacion CVSS v3.14.9
SeveridadMEDIUM
Vector CVSSCVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:N
Vector de ataqueNETWORK
ComplejidadHIGH
Privilegios requeridosLOW
Interaccion usuarioNONE
Publicado10/16/2024
Ultima modificacion10/30/2024
Fuentenvd
Avistamientos honeypot0
Productos afectados
wordpress:wordpress
Debilidades (CWE)
CWE-79
Referencias
https://core.trac.wordpress.org/changeset/53961(security@wordfence.com)
https://wordpress.org/news/2022/08/wordpress-6-0-2-security-and-maintenance-release/(security@wordfence.com)
Correlaciones IOC
Sin correlaciones registradas
This product uses data from the NVD API but is not endorsed or certified by the NVD.