CVE-2022-34853: WordPress Team plugin <= 1.2.6 - Multiple Authenticated Persistent Cross-Site Scripting (XSS) vulnerabilities
Published Jul 22, 2022
·Updated
Multiple Authenticated (contributor or higher user role) Persistent Cross-Site Scripting (XSS) vulnerabilities in wpWax Team plugin <= 1.2.6 at WordPress.
Affected Software
1 affected component
wpWax Team Wordpress<=1.2.6
Event History
Jul 22, 2022
CVE Published
via MITRE·04:49 PM
Data Sourced
via MITRE·04:49 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2022-34853.
2
What is the severity of CVE-2022-34853?
The severity of CVE-2022-34853 is medium with a CVSS score of 5.4.
3
What is the affected software for CVE-2022-34853?
The affected software for CVE-2022-34853 is the wpWax Team plugin <= 1.2.6 at WordPress.
4
How can I fix CVE-2022-34853?
To fix CVE-2022-34853, update wpWax Team plugin to version 1.2.7 or higher.
5
What is the CWE category for CVE-2022-34853?
The CWE category for CVE-2022-34853 is CWE-79 (Cross-Site Scripting).