First published: Fri Jan 28 2022(Updated: )
Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability discovered in Ultimate Reviews WordPress plugin (versions <= 3.0.15).
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Etoile Web Design Ultimate Reviews | <=3.0.15 | |
<=3.0.15 |
Update to 3.0.16 or higher version.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability discovered in the Ultimate Reviews WordPress plugin (versions <= 3.0.15).
The severity of CVE-2022-23979 is medium with a CVSS score of 4.8.
The vulnerability allows authenticated users with admin+ privileges to perform stored cross-site scripting attacks.
Update to a version of the Ultimate Reviews plugin that is higher than 3.0.15.
You can find more information about CVE-2022-23979 at the following references: [1](https://patchstack.com/database/vulnerability/ultimate-reviews/wordpress-ultimate-reviews-plugin-3-0-15-authenticated-stored-cross-site-scripting-xss-vulnerability) [2](https://wordpress.org/plugins/ultimate-reviews/#developers)