CVE-2022-3985: Videojs HTML5 Player < 1.1.9 - Contributor+ Stored XSS
The Videojs HTML5 Player WordPress plugin before 1.1.9 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-3985?
The severity of CVE-2022-3985 is classified as medium, primarily due to its potential for Stored Cross-Site Scripting attacks.
How do I fix CVE-2022-3985?
To fix CVE-2022-3985, update the Videojs HTML5 Player WordPress plugin to version 1.1.9 or later.
Who is affected by CVE-2022-3985?
Users with roles as low as contributor can be affected by CVE-2022-3985, enabling them to exploit the vulnerability.
What type of vulnerability is CVE-2022-3985?
CVE-2022-3985 is a Stored Cross-Site Scripting (XSS) vulnerability.
What software versions are impacted by CVE-2022-3985?
CVE-2022-3985 affects Videojs HTML5 Player WordPress plugin versions prior to 1.1.9.