CVE-2022-3906: Easy Form Builder < 3.4.0 - Admin+ Stored XSS
The Easy Form Builder WordPress plugin before 3.4.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfilteredhtml capability is disallowed (for example in multisite setup).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-3906?
CVE-2022-3906 is classified as a medium severity vulnerability due to its potential to allow Stored Cross-Site Scripting attacks.
How do I fix CVE-2022-3906?
To fix CVE-2022-3906, update the Easy Form Builder plugin to version 3.4.0 or later.
Who is affected by CVE-2022-3906?
CVE-2022-3906 affects users of the Easy Form Builder WordPress plugin prior to version 3.4.0.
What kind of attacks can CVE-2022-3906 allow?
CVE-2022-3906 can allow high privilege users to perform Stored Cross-Site Scripting attacks.
Does CVE-2022-3906 affect multisite WordPress installations?
Yes, CVE-2022-3906 can affect multisite WordPress installations even when the unfiltered_html capability is disallowed.