First published: Mon Mar 07 2022(Updated: )
The CP Blocks WordPress plugin before 1.0.15 does not sanitise and escape its "License ID" settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html is disallowed.
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
Dwbooster Cp Blocks | <1.0.15 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this vulnerability is CVE-2022-0448.
The affected software for this vulnerability is the CP Blocks WordPress plugin before version 1.0.15.
The severity of CVE-2022-0448 is medium.
The CWE ID associated with CVE-2022-0448 is CWE-79.
The vulnerability can be exploited by high privilege users to perform Cross-Site Scripting (XSS) attacks, even when the unfiltered_html is disallowed.