CVE-2022-4200: Login with Cognito <= 1.4.8 - Admin+ Stored XSS
The Login with Cognito WordPress plugin through 1.4.8 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfilteredhtml capability is disallowed (for example in multisite setup).
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2022-4200.
What is the title of this vulnerability?
The title of this vulnerability is 'The Login with Cognito WordPress plugin through 1.4.8 does not sanitise and escape some of its settings'.
What is the severity of CVE-2022-4200?
The severity of CVE-2022-4200 is medium with a CVSS score of 4.8.
How does CVE-2022-4200 affect the Login with Cognito WordPress plugin?
CVE-2022-4200 affects the Login with Cognito WordPress plugin through version 1.4.8.
What is the impact of CVE-2022-4200?
CVE-2022-4200 could allow high privilege users, such as admins, to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.