First published: Mon Jan 16 2023(Updated: )
The 3D FlipBook WordPress plugin through 1.13.2 does not validate or escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks against high privilege users like administrators.
Credit: contact@wpscan.com contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
3D FlipBook | <1.13.3 | |
3D FlipBook | <1.13.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-4453 is a vulnerability in the 3D FlipBook WordPress plugin through version 1.13.2 that allows stored cross-site scripting attacks.
CVE-2022-4453 has a severity rating of 5.4, which is considered medium.
The affected software is the 3D FlipBook WordPress plugin through version 1.13.2.
CVE-2022-4453 can be exploited by users with a role as low as Contributor who can perform stored cross-site scripting attacks against high privilege users like administrators.
CVE-2022-4453 can be fixed by updating the 3D FlipBook WordPress plugin to version 1.13.3 or higher.