CVE-2022-0706: Easy Digital Downloads < 2.11.6 - Admin+ Stored Cross-Site Scripting
The Easy Digital Downloads WordPress plugin before 2.11.6 does not sanitise and escape the Downloadable File Name in the Logs, which could allow high privilege users to perform Cross-Site Scripting attacks when the unfilteredhtml capability is disallowed
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2022-0706?
CVE-2022-0706 is a vulnerability found in the Easy Digital Downloads WordPress plugin before version 2.11.6.
What is the severity of CVE-2022-0706?
CVE-2022-0706 has a severity level of medium with a severity value of 4.8.
How does CVE-2022-0706 affect the Easy Digital Downloads plugin?
CVE-2022-0706 affects the Easy Digital Downloads plugin by not properly sanitizing and escaping the Downloadable File Name in the Logs, which could allow high privilege users to perform Cross-Site Scripting (XSS) attacks.
What is the potential impact of CVE-2022-0706?
The potential impact of CVE-2022-0706 is that high privilege users could exploit the vulnerability to perform XSS attacks, gaining unauthorized access or altering the behavior of the affected WordPress site.
How can I fix CVE-2022-0706?
To fix CVE-2022-0706, update the Easy Digital Downloads WordPress plugin to version 2.11.6 or newer, which includes the necessary sanitization and escaping of the Downloadable File Name in the Logs.