CVE-2022-4197: Sliderby10Web < 1.2.53 - Admin+ Stored XSS
Published Dec 26, 2022
·Updated
The Sliderby10Web WordPress plugin before 1.2.53 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfilteredhtml capability is disallowed (for example in multisite setup).
Affected Software
1 affected component
10web Slider Wordpress<1.2.53
Event History
Dec 26, 2022
CVE Published
via MITRE·12:28 PM
Data Sourced
via MITRE·12:28 PM
DescriptionWeakness
Data Sourced
via NVD·01:15 PM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the vulnerability ID of the Sliderby10Web WordPress plugin?
The vulnerability ID is CVE-2022-4197.
2
What is the severity of CVE-2022-4197?
The severity of CVE-2022-4197 is medium with a severity value of 4.8.
3
How does the Sliderby10Web WordPress plugin before 1.2.53 handle its settings?
The Sliderby10Web WordPress plugin before 1.2.53 does not sanitize and escape some of its settings.
4
Who can exploit CVE-2022-4197?
High privilege users, such as admins, can exploit CVE-2022-4197.
5
Can the Sliderby10Web WordPress plugin be vulnerable in a multisite setup?
Yes, the Sliderby10Web WordPress plugin can be vulnerable in a multisite setup.