CVE-2022-4464: Themify Portfolio Post < 1.2.1 - Contributor+ Stored XSS
Themify Portfolio Post WordPress plugin before 1.2.1 does not validate and escapes some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as a contributor to perform Stored Cross-Site Scripting attacks, which could be used against high privileged users such as admin.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-4464?
CVE-2022-4464 is considered a high severity vulnerability due to its potential for allowing Stored Cross-Site Scripting attacks.
How do I fix CVE-2022-4464?
To fix CVE-2022-4464, update the Themify Portfolio Post plugin to version 1.2.1 or later.
Who is affected by CVE-2022-4464?
CVE-2022-4464 affects users of the Themify Portfolio Post WordPress plugin version prior to 1.2.1.
What type of attack can CVE-2022-4464 enable?
CVE-2022-4464 can enable Stored Cross-Site Scripting attacks by allowing unvalidated data to be output on a page.
Can a contributor role exploit CVE-2022-4464?
Yes, users with as little as a contributor role can exploit CVE-2022-4464, increasing its risk.