First published: Mon Aug 01 2022(Updated: )
The Flexi Quote Rotator WordPress plugin through 0.9.4 does not sanitise and escape its settings, allowing high privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
Flexi Quote Rotator Project Flexi Quote Rotator | <=0.9.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-2328 is a vulnerability in the Flexi Quote Rotator WordPress plugin through version 0.9.4 that allows for Cross-Site Scripting attacks.
The severity of CVE-2022-2328 is medium with a severity value of 4.8.
CVE-2022-2328 affects the Flexi Quote Rotator WordPress plugin through version 0.9.4 by allowing high privilege users like admin to perform Cross-Site Scripting attacks.
Cross-Site Scripting (XSS) attack is a vulnerability that allows attackers to inject malicious scripts into web pages viewed by other users.
To fix the CVE-2022-2328 vulnerability, it is recommended to update the Flexi Quote Rotator WordPress plugin to a version that has fixed this issue.