CVE-2022-1010: Login using WordPress Users < 1.13.4 - Admin+ Stored Cross-Site Scripting
Published Jun 27, 2022
·Updated
The Login using WordPress Users ( WP as SAML IDP ) WordPress plugin before 1.13.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks when the unfilteredhtml capability is disallowed (for example in multisite setup)
Affected Software
1 affected component
miniOrange Login Using Wordpress Users Wordpress<1.1.34
Event History
Jun 27, 2022
CVE Published
via MITRE·08:55 AM
Data Sourced
via MITRE·08:55 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this security issue?
The vulnerability ID for this security issue is CVE-2022-1010.
2
What is the severity of CVE-2022-1010?
The severity of CVE-2022-1010 is medium with a score of 4.8.
3
How does the Login using WordPress Users plugin before 1.13.4 handle its settings?
The Login using WordPress Users plugin before 1.13.4 does not sanitize and escape some of its settings.
4
What can high privilege users potentially do with the Login using WordPress Users plugin before 1.13.4?
High privilege users such as admins can potentially perform Stored Cross-Site Scripting attacks with the plugin.
5
What is the affected software version of the Login using WordPress Users plugin?
The affected software version of the Login using WordPress Users plugin is up to version 1.1.34.