CVE-2022-44742: WordPress Community Events Plugin <= 1.4.8 is vulnerable to Cross Site Scripting (XSS)
Published Mar 23, 2023
·Updated
Auth. (admin+) Stored Cross-Site Scripting vulnerability in Yannick Lefebvre Community Events plugin <= 1.4.8 versions.
Affected Software
1 affected component
Community Events Project Community Events Wordpress<1.4.9
Remediation
Information
Update to 1.4.9 or a higher version.
Event History
Mar 23, 2023
CVE Published
via MITRE·11:33 AM
Data Sourced
via MITRE·11:33 AM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2022-44742?
CVE-2022-44742 is classified as a high severity vulnerability due to its potential for causing significant security risks.
2
How do I fix CVE-2022-44742?
To mitigate CVE-2022-44742, update the Community Events plugin to version 1.4.9 or later.
3
Who is affected by CVE-2022-44742?
Users of the Community Events plugin version 1.4.8 or earlier are affected by CVE-2022-44742.
4
What type of vulnerability is CVE-2022-44742?
CVE-2022-44742 is a stored cross-site scripting (XSS) vulnerability that can be exploited by authenticated users.
5
Is user authentication required to exploit CVE-2022-44742?
Yes, CVE-2022-44742 requires administrative user authentication for exploitation.