First published: Mon Jan 16 2023(Updated: )
The Sidebar Widgets by CodeLights WordPress plugin through 1.4 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as a contributor to perform Stored Cross-Site Scripting attacks, which could be used against high-privilege users such as admins.
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
Codelights-shortcodes-and-widgets Project Codelights-shortcodes-and-widgets | <=1.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this issue is CVE-2022-4460.
The severity of CVE-2022-4460 is medium with a CVSS score of 5.4.
The affected software is the Sidebar Widgets by CodeLights WordPress plugin version 1.4.
The CWE ID of this vulnerability is CWE-79.
An attacker can exploit CVE-2022-4460 by performing Stored Cross-Site Scripting (XSS) attacks.