CVE-2022-2384: Digital Publications by Supsystic < 1.7.4 - Admin+ Stored Cross-Site Scripting
The Digital Publications by Supsystic WordPress plugin before 1.7.4 does not sanitise and escape its settings, allowing high privilege users such as admin to perform cross-Site Scripting attacks even when the unfilteredhtml capability is disallowed.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2022-2384.
What is the severity of CVE-2022-2384?
The severity of CVE-2022-2384 is medium with a severity value of 4.8.
What is the affected software by CVE-2022-2384?
The affected software by CVE-2022-2384 is the Digital Publications by Supsystic WordPress plugin before version 1.7.4.
What is the description of CVE-2022-2384?
CVE-2022-2384 is a vulnerability in the Digital Publications by Supsystic WordPress plugin before version 1.7.4 that allows high privilege users to perform cross-Site Scripting attacks.
Is there a fix available for CVE-2022-2384?
Yes, the fix for CVE-2022-2384 is to update the Digital Publications by Supsystic WordPress plugin to version 1.7.4 or later.