CVE-2022-1945: Coming Soon and Maintenance by Colorlib < 1.0.99 - Admin+ Stored Cross Site Scripting
The Coming Soon & Maintenance Mode by Colorlib WordPress plugin before 1.0.99 does not sanitize and escape some settings, allowing high privilege users such as admin to perform Stored Cross-Site Scripting when unfilteredhtml is disallowed (for example in multisite setup)
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-1945?
CVE-2022-1945 has been classified as a high severity vulnerability due to its potential for Stored Cross-Site Scripting attacks.
How do I fix CVE-2022-1945?
To fix CVE-2022-1945, update the Colorlib Coming Soon & Maintenance Mode plugin to version 1.0.99 or later.
Who is affected by CVE-2022-1945?
CVE-2022-1945 affects users of the Colorlib Coming Soon & Maintenance Mode WordPress plugin before version 1.0.99.
What is Stored Cross-Site Scripting in CVE-2022-1945?
Stored Cross-Site Scripting in CVE-2022-1945 occurs when an attacker injects malicious scripts that are stored and executed by users of the compromised site.
Can unprivileged users exploit CVE-2022-1945?
No, unprivileged users cannot exploit CVE-2022-1945 as it requires high privilege access to perform the attack.