CVE-2022-40694: WordPress News Announcement Scroll plugin <= 8.8.8 - Auth. Stored Cross-Site Scripting (XSS) vulnerability
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in News Announcement Scroll plugin <= 8.8.8 on WordPress.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress News Announcement Scroll pluginto a version that resolves this vulnerability.Fixed in 9.0.0
Event History
Frequently Asked Questions
What is the severity of CVE-2022-40694?
CVE-2022-40694 has a medium severity rating due to its potential to allow stored Cross-Site Scripting attacks.
How do I fix CVE-2022-40694?
To fix CVE-2022-40694, update the News Announcement Scroll plugin to version 8.8.9 or later.
Who is affected by CVE-2022-40694?
CVE-2022-40694 affects users of the News Announcement Scroll plugin version 8.8.8 and below on WordPress.
What type of vulnerability is CVE-2022-40694?
CVE-2022-40694 is an authenticated stored Cross-Site Scripting (XSS) vulnerability.
Are there any workarounds for CVE-2022-40694?
Currently, the best workaround for CVE-2022-40694 is to disable or delete the vulnerable plugin until it is updated.