CVE-2022-2430: Visual Composer Website Builder <= 45.0 - Authenticated Stored Cross-Site Scripting via 'Text Block'
The Visual Composer Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Text Block' feature in versions up to, and including, 45.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with access to the visual composer editor to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2022-2430?
CVE-2022-2430 is rated as a high-severity vulnerability due to its potential for stored cross-site scripting attacks.
How do I fix CVE-2022-2430?
To fix CVE-2022-2430, update the Visual Composer Website Builder plugin to version 45.1 or later.
Who is affected by CVE-2022-2430?
CVE-2022-2430 affects users of the Visual Composer Website Builder plugin for WordPress versions up to and including 45.0.
What type of vulnerability is CVE-2022-2430?
CVE-2022-2430 is a stored cross-site scripting (XSS) vulnerability that allows attackers to inject malicious scripts.
What is the impact of CVE-2022-2430?
The impact of CVE-2022-2430 can lead to unauthorized access to sensitive information and the execution of malicious scripts in the context of users' browsers.