First published: Mon Dec 12 2022(Updated: )
The Image Hover Effects WordPress plugin before 5.5 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
Credit: contact@wpscan.com contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
<=5.3 | ||
Webdevocean Image Hover Effects | <=5.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2022-4010.
The title of the vulnerability is 'The Image Hover Effects WordPress plugin before 5.5 does not sanitise and escape some of its settings'.
The severity of CVE-2022-4010 is medium, with a severity value of 4.8.
The affected software is the Image Hover Effects WordPress plugin version up to and including 5.3.
The CWE category of CVE-2022-4010 is CWE-79, Cross-Site Scripting (XSS).