CVE-2022-2194: Accept Stripe Payments < 2.0.64 - Admin+ Stored Cross-Site Scripting
Published Jul 17, 2022
·Updated
The Accept Stripe Payments WordPress plugin before 2.0.64 does not sanitize and escape some of its settings, allowing high privilege users such as admin to perform cross-Site Scripting attacks even when the unfilteredhtml capability is disallowed.
Affected Software
1 affected component
Tipsandtricks-hq Accept Stripe Wordpress<2.0.64
Event History
Jul 17, 2022
CVE Published
via MITRE·10:37 AM
Data Sourced
via MITRE·10:37 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2022-2194.
2
What is the severity of CVE-2022-2194?
The severity of CVE-2022-2194 is medium.
3
What is the affected software of CVE-2022-2194?
The affected software of CVE-2022-2194 is the Accept Stripe Payments WordPress plugin before version 2.0.64.
4
What is the impact of CVE-2022-2194?
CVE-2022-2194 allows high privilege users to perform cross-site scripting attacks even when the unfiltered_html capability is disallowed.
5
Is there a fix available for CVE-2022-2194?
Yes, upgrading to version 2.0.64 or later of the Accept Stripe Payments WordPress plugin fixes CVE-2022-2194.