First published: Mon Oct 24 2022(Updated: )
Broken Access Control vulnerability leading to Stored Cross-Site Scripting (XSS) in Traffic Manager plugin <= 1.4.5 on WordPress.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Riverbed SteelApp Traffic Manager | <=1.4.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-42460 has a high severity rating due to its potential for allowing stored cross-site scripting attacks.
To mitigate CVE-2022-42460, update the Traffic Manager plugin to version 1.4.6 or later.
CVE-2022-42460 can lead to stored cross-site scripting (XSS) attacks, which may compromise user data and website integrity.
If you are using Traffic Manager plugin version 1.4.5 or earlier on WordPress, your site is vulnerable to CVE-2022-42460.
Users of the Traffic Manager plugin for WordPress versions up to and including 1.4.5 are affected by CVE-2022-42460.