CVE-2022-40963: WordPress WP Page Builder plugin <= 1.2.6 - Multiple Auth. Stored Cross-Site Scripting (XSS) vulnerabilities
Published Nov 18, 2022
·Updated
Multiple Auth. (author+) Stored Cross-Site Scripting (XSS) vulnerabilities in WP Page Builder plugin <= 1.2.6 on WordPress.
Affected Software
1 affected component
Themeum Wp Page Builder Wordpress<1.2.7
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress WP Page Builder pluginto a version that resolves this vulnerability.Fixed in 1.2.7
Event History
Nov 18, 2022
CVE Published
via MITRE·10:19 PM
Data Sourced
via MITRE·10:19 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·11:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2022-40963?
The severity of CVE-2022-40963 is medium with a CVSS score of 5.4.
2
What is the affected software for CVE-2022-40963?
The affected software for CVE-2022-40963 is WP Page Builder plugin version <= 1.2.6 on WordPress.
3
How can I fix CVE-2022-40963?
To fix CVE-2022-40963, update your WP Page Builder plugin to version 1.2.7 or higher.
4
What is the Common Weakness Enumeration (CWE) for CVE-2022-40963?
The Common Weakness Enumeration (CWE) for CVE-2022-40963 is CWE-79.
5
Where can I find more information about CVE-2022-40963?
You can find more information about CVE-2022-40963 on the Patchstack database and the WordPress plugin page.