CVE-2022-1321: miniOrange's Google Authenticator < 5.5.6 - Admin+ Stored Cross-Site Scripting
The miniOrange's Google Authenticator WordPress plugin before 5.5.6 does not sanitise and escape some of its settings, leading to malicious users with administrator privileges to store malicious Javascript code leading to Cross-Site Scripting attacks when unfilteredhtml is disallowed (for example in multisite setup)
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this vulnerability?
The vulnerability ID is CVE-2022-1321.
What is the title of this vulnerability?
The title of this vulnerability is 'The miniOrange's Google Authenticator WordPress plugin before 5.5.6 does not sanitise and escape som...'.
What is the severity of CVE-2022-1321?
The severity of CVE-2022-1321 is medium with a CVSS score of 4.8.
Which software is affected by CVE-2022-1321?
The miniOrange's Google Authenticator WordPress plugin versions up to and exclusive of 5.5.6 are affected.
How can this vulnerability be exploited?
This vulnerability can be exploited by malicious users with administrator privileges to store malicious Javascript code leading to Cross-Site Scripting attacks when unfiltered_html is disallowed.