First published: Thu Nov 03 2022(Updated: )
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in JumpDEMAND Inc. 4ECPS Web Forms plugin <= 0.2.17 on WordPress.
Credit: audit@patchstack.com audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
4ECPS Web Forms | <=0.2.17 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-44628 is categorized as a high-severity vulnerability due to its potential for stored Cross-Site Scripting exploitation.
To fix CVE-2022-44628, update the 4ECPS Web Forms plugin to version 0.2.18 or later.
CVE-2022-44628 affects WordPress sites using the 4ECPS Web Forms plugin version 0.2.17 or earlier.
CVE-2022-44628 allows authenticated administrators to inject malicious scripts via stored Cross-Site Scripting.
If you cannot update, a temporary workaround is to disable the 4ECPS Web Forms plugin until an update can be applied.