CVE-2022-2565: Best Payments Plugin for WP < 4.2.1 - Unauthenticated Stored Cross-Site Scripting
The Simple Payment Donations & Subscriptions WordPress plugin before 4.2.1 does not sanitise and escape user input given in its forms, which could allow unauthenticated attackers to perform Cross-Site Scripting attacks against admins
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-2565?
CVE-2022-2565 is classified as a medium severity vulnerability due to its potential for Cross-Site Scripting attacks.
How do I fix CVE-2022-2565?
To fix CVE-2022-2565, update the Simple Payment Donations & Subscriptions plugin to version 4.2.1 or higher.
Who is impacted by CVE-2022-2565?
CVE-2022-2565 primarily affects users of the Simple Payment Donations & Subscriptions WordPress plugin prior to version 4.2.1.
What type of vulnerability is CVE-2022-2565?
CVE-2022-2565 is a Cross-Site Scripting (XSS) vulnerability caused by improper sanitization and escaping of user input.
Can CVE-2022-2565 be exploited remotely?
Yes, CVE-2022-2565 can be exploited remotely by unauthenticated attackers targeting the affected WordPress plugin.