← Back to CVEs
CVE-2022-4973
MEDIUM4.9
Description
WordPress Core, in versions up to 6.0.2, is vulnerable to Authenticated Stored Cross-Site Scripting that can be exploited by users with access to the WordPress post and page editor, typically consisting of Authors, Contributors, and Editors making it possible to inject arbitrary web scripts into posts and pages that execute if the the_meta(); function is called on that page.
CVE Details
CVSS v3.1 Score4.9
SeverityMEDIUM
CVSS VectorCVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:N
Attack VectorNETWORK
ComplexityHIGH
Privileges RequiredLOW
User InteractionNONE
Published10/16/2024
Last Modified10/30/2024
Sourcenvd
Honeypot Sightings0
Affected Products
wordpress:wordpress
Weaknesses (CWE)
CWE-79
References
https://core.trac.wordpress.org/changeset/53961(security@wordfence.com)
https://wordpress.org/news/2022/08/wordpress-6-0-2-security-and-maintenance-release/(security@wordfence.com)
IOC Correlations
No correlations recorded
This product uses data from the NVD API but is not endorsed or certified by the NVD.