CVE-2022-4469: Simple Membership < 4.2.2 - Contributor+ Stored XSS
The Simple Membership WordPress plugin before 4.2.2 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admin.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-4469?
CVE-2022-4469 is considered to have a medium severity due to the potential for Stored Cross-Site Scripting attacks.
How do I fix CVE-2022-4469?
To fix CVE-2022-4469, update the Simple Membership WordPress plugin to version 4.2.2 or later.
Who is affected by CVE-2022-4469?
CVE-2022-4469 affects users of the Simple Membership WordPress plugin before version 4.2.2.
What type of vulnerability is CVE-2022-4469?
CVE-2022-4469 is a Stored Cross-Site Scripting vulnerability resulting from improper validation and escaping of shortcode attributes.
What can attackers do with CVE-2022-4469?
Attackers can exploit CVE-2022-4469 to inject malicious scripts into web pages, which can then be executed by users visiting those pages.