CVE-2022-25618: WordPress wpDataTables plugin <= 2.1.27 - Stored Cross-Site Scripting (XSS) vulnerability
Published Apr 4, 2022
·Updated
Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability in wpDataTables (WordPress plugin) versions <= 2.1.27
Affected Software
1 affected component
Tms-outsource Wpdatatables Lite Wordpress<2.1.28
Remediation
Information
Update to 2.1.28 or higher version.
Event History
Apr 4, 2022
CVE Published
via MITRE·07:46 PM
Data Sourced
via MITRE·07:46 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2022-25618?
CVE-2022-25618 has a medium severity rating due to its potential for exploiting stored XSS vulnerabilities.
2
How do I fix CVE-2022-25618?
To fix CVE-2022-25618, update the wpDataTables plugin to version 2.1.28 or later.
3
Who is affected by CVE-2022-25618?
CVE-2022-25618 affects users of wpDataTables plugin versions 2.1.27 and earlier on WordPress.
4
What type of vulnerability is CVE-2022-25618?
CVE-2022-25618 is categorized as an authenticated stored cross-site scripting (XSS) vulnerability.
5
Can CVE-2022-25618 be exploited remotely?
CVE-2022-25618 requires administration privileges, meaning that while it is exploitable, it requires a logged-in user with admin+ rights.