CVE-2022-0448: CP Blocks < 1.0.15 - Admin+ Stored Cross-Site Scripting
Published Mar 7, 2022
·Updated
The CP Blocks WordPress plugin before 1.0.15 does not sanitise and escape its "License ID" settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfilteredhtml is disallowed.
Affected Software
1 affected component
Dwbooster Cp Blocks Wordpress<1.0.15
Event History
Mar 7, 2022
CVE Published
via MITRE·08:16 AM
Data Sourced
via MITRE·08:16 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2022-0448.
2
What is the affected software for this vulnerability?
The affected software for this vulnerability is the CP Blocks WordPress plugin before version 1.0.15.
3
What is the severity of CVE-2022-0448?
The severity of CVE-2022-0448 is medium.
4
What is the CWE ID associated with CVE-2022-0448?
The CWE ID associated with CVE-2022-0448 is CWE-79.
5
How can the vulnerability be exploited?
The vulnerability can be exploited by high privilege users to perform Cross-Site Scripting (XSS) attacks, even when the unfiltered_html is disallowed.