First published: Mon Jul 11 2022(Updated: )
The WP-Paginate WordPress plugin before 2.1.9 does not escape one of its settings, which could allow high privilege users to perform Stored Cross-Site Scripting attacks when unfiltered_html is disallowed
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
Maxfoundry Wp-paginate | <2.1.9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-2050 is classified as a high severity vulnerability due to the potential for Stored Cross-Site Scripting attacks.
To fix CVE-2022-2050, update the WP-Paginate plugin to version 2.1.9 or later.
CVE-2022-2050 affects users of the WP-Paginate WordPress plugin prior to version 2.1.9.
CVE-2022-2050 allows high privilege users to perform Stored Cross-Site Scripting (XSS) attacks.
Yes, CVE-2022-2050 can be exploited when the unfiltered_html capability is disallowed for high privilege users.