CVE-2022-2398: WP Comments Fields < 4.1 - Admin+ Stored Cross-Site Scripting
Published Aug 8, 2022
·Updated
The WordPress Comments Fields WordPress plugin before 4.1 does not escape Field Error Message, which could allow high-privileged users to perform Cross-Site Scripting attacks even when unfilteredhtml is disallowed
Affected Software
1 affected component
Najeebmedia Wordpress Comments Fields Wordpress<4.1
Event History
Aug 8, 2022
CVE Published
via MITRE·01:48 PM
Data Sourced
via MITRE·01:48 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID for the WordPress Comments Fields plugin?
The vulnerability ID for the WordPress Comments Fields plugin is CVE-2022-2398.
2
What is the severity level of CVE-2022-2398?
CVE-2022-2398 has a severity level of medium.
3
What is the affected software for CVE-2022-2398?
The affected software for CVE-2022-2398 is the Najeebmedia Wordpress Comments Fields plugin version up to 4.1.
4
What is the risk of CVE-2022-2398?
CVE-2022-2398 poses a risk of Cross-Site Scripting (XSS) attacks.
5
How can the CVE-2022-2398 vulnerability be fixed?
To fix the CVE-2022-2398 vulnerability, update the Najeebmedia Wordpress Comments Fields plugin to version 4.1 or later.