CVE-2022-32970: WordPress Themify Portfolio Post Plugin <= 1.2.4 is vulnerable to Cross Site Scripting (XSS)
Auth. (editor+) Stored Cross-Site Scripting (XSS) vulnerability in Themify Themify Portfolio Post plugin <= 1.2.4 versions.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2022-32970?
The severity of CVE-2022-32970 is medium with a severity value of 5.4.
What is the vulnerability description of CVE-2022-32970?
CVE-2022-32970 is a stored Cross-Site Scripting (XSS) vulnerability in Themify Themify Portfolio Post plugin <= 1.2.4 versions, which allows authenticated users with editor+ privileges to inject malicious scripts.
What software versions are affected by CVE-2022-32970?
CVE-2022-32970 affects Themify Themify Portfolio Post plugin versions up to and including 1.2.4.
How can I fix CVE-2022-32970?
To fix CVE-2022-32970, you should update the Themify Themify Portfolio Post plugin to version 1.2.5 or later.
What is the Common Weakness Enumeration (CWE) for CVE-2022-32970?
The Common Weakness Enumeration (CWE) for CVE-2022-32970 is CWE-79, which refers to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting').