CVE-2022-41132: WordPress Ezoic plugin <= 2.8.8 - Unauthenticated Plugin Settings Change Leading To Stored XSS Vulnerability
Unauthenticated Plugin Settings Change Leading To Stored XSS Vulnerability in Ezoic plugin <= 2.8.8 on WordPress.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Ezoic pluginto a version that resolves this vulnerability.Fixed in 2.8.9
Event History
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2022-41132.
What is the severity of CVE-2022-41132?
The severity of CVE-2022-41132 is medium with a severity value of 6.1.
What is the affected software for CVE-2022-41132?
The affected software for CVE-2022-41132 is the Ezoic plugin version <= 2.8.8 on WordPress.
What is the CWE ID for CVE-2022-41132?
The CWE ID for CVE-2022-41132 is CWE-79 and CWE-264.
Is there a patch available for CVE-2022-41132?
Yes, a patch is available for CVE-2022-41132. Please refer to the following link: [Patchstack - CVE-2022-41132](https://patchstack.com/database/vulnerability/ezoic-integration/wordpress-ezoic-plugin-2-8-8-unauthenticated-plugin-settings-change-leading-to-stored-xss-vulnerability?_s_id=cve)