First published: Mon Apr 18 2022(Updated: )
The Hummingbird WordPress plugin before 3.3.2 does not sanitise and escape the Config Name, which could allow high privilege users, such as admin to perform cross-Site Scripting attacks even when the unfiltered_html capability is disallowed
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
Hummingbird | <3.3.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2022-0994.
The severity of CVE-2022-0994 is medium with a score of 4.8.
The affected software is the Hummingbird WordPress plugin before version 3.3.2.
CVE-2022-0994 allows high privilege users, such as admins, to perform cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.
Yes, the fix for CVE-2022-0994 is to update to version 3.3.2 or later of the Hummingbird WordPress plugin.