CVE-2022-2152: Duplicate Page and Post Plugin < 2.8 - Admin+ Stored Cross-Site Scripting
Published Aug 15, 2022
·Updated
The Duplicate Page and Post WordPress plugin before 2.8 does not sanitise and escape its settings, allowing high privilege users such as admin to perform Cross-Site Scripting attacks even when the unfilteredhtml capability is disallowed.
Affected Software
1 affected component
Duplicate Page And Post Project Duplicate Page And Post Wordpress<2.8
Event History
Aug 15, 2022
CVE Published
via MITRE·08:36 AM
Data Sourced
via MITRE·08:36 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2022-2152.
2
What is the severity of CVE-2022-2152?
The severity of CVE-2022-2152 is medium with a severity value of 4.8.
3
What is the affected software?
The affected software is the Duplicate Page and Post WordPress plugin before version 2.8.
4
What is the risk associated with CVE-2022-2152?
CVE-2022-2152 allows high privilege users to perform Cross-Site Scripting (XSS) attacks, even when the unfiltered_html capability is disallowed.
5
How can I mitigate the vulnerability CVE-2022-2152?
To mitigate CVE-2022-2152, update the Duplicate Page and Post WordPress plugin to version 2.8 or later.