CVE-2022-27859: WordPress Travel Management plugin <= 2.0 - Multiple Authenticated Stored Cross-Site Scripting (XSS) vulnerabilities
Multiple Authenticated (contributor or higher user role) Stored Cross-Site Scripting (XSS) vulnerabilities in Nicdark d.o.o. Travel Management plugin <= 2.0 at WordPress.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-27859?
CVE-2022-27859 is rated as a medium severity vulnerability due to its potential for exploited stored cross-site scripting.
How do I fix CVE-2022-27859?
To fix CVE-2022-27859, you should upgrade the Nicdark Travel Management plugin to a version higher than 2.0.
Who is affected by CVE-2022-27859?
Users with authenticated contributor or higher roles using versions of the Nicdark Travel Management plugin up to 2.0 are affected by CVE-2022-27859.
What type of vulnerability is CVE-2022-27859?
CVE-2022-27859 is a stored cross-site scripting (XSS) vulnerability that allows attackers to inject malicious scripts.
Can CVE-2022-27859 be exploited remotely?
CVE-2022-27859 can be exploited remotely by authenticated users with appropriate permissions, such as contributors.