CVE-2022-3922: Broken Link Checker < 1.11.20 - Admin+ Cross-Site Scripting
The Broken Link Checker WordPress plugin before 1.11.20 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfilteredhtml capability is disallowed (for example in multisite setup)
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2022-3922.
What is the severity level of CVE-2022-3922?
The severity level of CVE-2022-3922 is medium.
What is the affected software?
The affected software is the Broken Link Checker WordPress plugin before version 1.11.20.
How can high privilege users exploit CVE-2022-3922?
High privilege users, such as admin, can exploit CVE-2022-3922 to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.
Where can I find more information about CVE-2022-3922?
You can find more information about CVE-2022-3922 at the following reference: https://wpscan.com/vulnerability/78054bd7-cdc2-4b14-9b5c-30f10e802d6b