First published: Mon Jun 27 2022(Updated: )
The miniOrange's Google Authenticator WordPress plugin before 5.5.6 does not sanitise and escape some of its settings, leading to malicious users with administrator privileges to store malicious Javascript code leading to Cross-Site Scripting attacks when unfiltered_html is disallowed (for example in multisite setup)
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
Miniorange Google Authenticator | <5.5.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2022-1321.
The title of this vulnerability is 'The miniOrange's Google Authenticator WordPress plugin before 5.5.6 does not sanitise and escape som...'.
The severity of CVE-2022-1321 is medium with a CVSS score of 4.8.
The miniOrange's Google Authenticator WordPress plugin versions up to and exclusive of 5.5.6 are affected.
This vulnerability can be exploited by malicious users with administrator privileges to store malicious Javascript code leading to Cross-Site Scripting attacks when unfiltered_html is disallowed.