CVE-2022-40672: WordPress CPO Shortcodes plugin <= 1.5.0 - Authenticated Stored Cross-Site Scripting (XSS) vulnerability
Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability in CPO Shortcodes plugin <= 1.5.0 at WordPress.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-40672?
CVE-2022-40672 is an authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability in the CPO Shortcodes plugin version 1.5.0 and below for WordPress.
How severe is CVE-2022-40672?
CVE-2022-40672 has a severity rating of medium (4.8 out of 10).
Which software versions are affected by CVE-2022-40672?
CVE-2022-40672 affects version 1.5.0 and below of the CPO Shortcodes plugin for WordPress.
How can I fix CVE-2022-40672?
To fix CVE-2022-40672, you should update the CPO Shortcodes plugin to a version higher than 1.5.0.
Where can I find more information about CVE-2022-40672?
You can find more information about CVE-2022-40672 at the following references: [Patchstack](https://patchstack.com/database/vulnerability/cpo-shortcodes/wordpress-cpo-shortcodes-plugin-1-5-0-authenticated-stored-cross-site-scripting-xss-vulnerability/_s_id=cve) and [WordPress.org](https://wordpress.org/plugins/cpo-shortcodes/).