First published: Mon Jun 27 2022(Updated: )
The Nested Pages WordPress plugin before 3.1.21 does not escape and sanitize the some of its settings, which could allow high privilege users to perform Stored Cross-Site Scripting attacks when the unfiltered_html is disallowed
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
Kyle Phillips Nested Pages | <3.1.21 | |
Nested Pages | <3.1.21 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-1990 is classified as a high severity vulnerability due to the potential for Stored Cross-Site Scripting attacks.
To fix CVE-2022-1990, update the Nested Pages WordPress plugin to version 3.1.21 or later.
CVE-2022-1990 affects users of the Nested Pages WordPress plugin versions prior to 3.1.21.
CVE-2022-1990 is a Stored Cross-Site Scripting (XSS) vulnerability.
Yes, administrators can mitigate CVE-2022-1990 by ensuring that the Nested Pages plugin is updated to the latest version.