CVE-2022-0876: Social comments by WpDevArt < 2.5.0 - Admin+ Stored Cross-Site Scripting
The Social comments by WpDevArt WordPress plugin before 2.5.0 does not sanitise and escape its settings, allowing high privilege users such as admin to perform cross-Site Scripting attacks even when unfilteredhtml is disallowed
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-0876?
CVE-2022-0876 is a vulnerability in the Social comments by WpDevArt WordPress plugin before version 2.5.0 that allows high privilege users to perform cross-site scripting (XSS) attacks.
How does CVE-2022-0876 impact WordPress?
CVE-2022-0876 allows high privilege users, such as admins, to exploit the vulnerability in the Social comments by WpDevArt WordPress plugin to perform XSS attacks even when unfiltered_html is disallowed.
What is the severity of CVE-2022-0876?
The severity of CVE-2022-0876 is rated as medium with a severity value of 4.8.
How can I fix CVE-2022-0876?
To fix CVE-2022-0876, you should update the Social comments by WpDevArt WordPress plugin to version 2.5.0 or higher.
What is the CWE classification for CVE-2022-0876?
CVE-2022-0876 is classified under CWE-79, which is the category for Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting').