CVE-2022-3933: Essential Real Estate < 3.9.6 - Reflected Cross-Site-Scripting
Published Dec 12, 2022
·Updated
The Essential Real Estate WordPress plugin before 3.9.6 does not sanitize and escapes some parameters, which could allow users with a role as low as Admin to perform Cross-Site Scripting attacks.
Affected Software
1 affected component
G5Theme Essential Real Estate Wordpress<3.9.6
Event History
Dec 12, 2022
CVE Published
via MITRE·05:54 PM
Data Sourced
via MITRE·05:54 PM
DescriptionWeakness
Data Sourced
via NVD·06:15 PM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for the Essential Real Estate WordPress plugin?
The vulnerability ID for the Essential Real Estate WordPress plugin is CVE-2022-3933.
2
What is the severity rating of CVE-2022-3933?
CVE-2022-3933 has a severity rating of medium.
3
What is the affected software for CVE-2022-3933?
The affected software for CVE-2022-3933 is the Essential Real Estate WordPress plugin before version 3.9.6.
4
What is the potential impact of CVE-2022-3933?
CVE-2022-3933 could allow users with a role as low as Admin to perform Cross-Site Scripting attacks.
5
How can I fix CVE-2022-3933?
To fix CVE-2022-3933, update the Essential Real Estate WordPress plugin to version 3.9.6 or later.