CVE-2022-4448: GiveWP < 2.24.0 - Contributor+ Stored XSS
Published Feb 13, 2023
·Updated
The GiveWP WordPress plugin before 2.24.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks
Affected Software
1 affected component
GiveWP GiveWP WordPress<2.24.0
Event History
Feb 13, 2023
CVE Published
via MITRE·02:32 PM
Data Sourced
via MITRE·02:32 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID for the GiveWP WordPress plugin?
The vulnerability ID for the GiveWP WordPress plugin is CVE-2022-4448.
2
What is the severity of CVE-2022-4448?
The severity of CVE-2022-4448 is medium with a score of 5.4.
3
What is the affected software for CVE-2022-4448?
The affected software for CVE-2022-4448 is the GiveWP WordPress plugin version up to exclusive 2.24.0.
4
What is the CWE ID for CVE-2022-4448?
The CWE ID for CVE-2022-4448 is CWE-79.
5
How can users mitigate the vulnerability in the GiveWP WordPress plugin?
Users should update to version 2.24.0 or higher of the GiveWP WordPress plugin to mitigate the vulnerability.