CVE-2022-44628: WordPress 4ECPS Web Forms plugin <= 0.2.17 - Auth. Stored Cross-Site Scripting (XSS) vulnerability
Published Nov 3, 2022
·Updated
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in JumpDEMAND Inc. 4ECPS Web Forms plugin <= 0.2.17 on WordPress.
Affected Software
1 affected component
JumpDEMAND 4ecps Web Forms Wordpress<=0.2.17
Event History
Nov 3, 2022
CVE Published
via MITRE·07:32 PM
Data Sourced
via MITRE·07:32 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2022-44628?
CVE-2022-44628 is categorized as a high-severity vulnerability due to its potential for stored Cross-Site Scripting exploitation.
2
How do I fix CVE-2022-44628?
To fix CVE-2022-44628, update the 4ECPS Web Forms plugin to version 0.2.18 or later.
3
Who is affected by CVE-2022-44628?
CVE-2022-44628 affects WordPress sites using the 4ECPS Web Forms plugin version 0.2.17 or earlier.
4
What type of attack does CVE-2022-44628 allow?
CVE-2022-44628 allows authenticated administrators to inject malicious scripts via stored Cross-Site Scripting.
5
Is there a workaround for CVE-2022-44628 if I cannot update?
If you cannot update, a temporary workaround is to disable the 4ECPS Web Forms plugin until an update can be applied.