CVE-2022-23979: WordPress Ultimate Reviews plugin <= 3.0.15 - Authenticated Stored Cross-Site Scripting (XSS) vulnerability
Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability discovered in Ultimate Reviews WordPress plugin (versions <= 3.0.15).
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the vulnerability CVE-2022-23979?
Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability discovered in the Ultimate Reviews WordPress plugin (versions <= 3.0.15).
What is the severity of CVE-2022-23979?
The severity of CVE-2022-23979 is medium with a CVSS score of 4.8.
How does the CVE-2022-23979 vulnerability affect the Ultimate Reviews plugin?
The vulnerability allows authenticated users with admin+ privileges to perform stored cross-site scripting attacks.
How can I fix CVE-2022-23979?
Update to a version of the Ultimate Reviews plugin that is higher than 3.0.15.
Where can I find more information about CVE-2022-23979?
You can find more information about CVE-2022-23979 at the following references: [1](https://patchstack.com/database/vulnerability/ultimate-reviews/wordpress-ultimate-reviews-plugin-3-0-15-authenticated-stored-cross-site-scripting-xss-vulnerability) [2](https://wordpress.org/plugins/ultimate-reviews/#developers)