CVE-2022-4482: Carousel, Slider, Gallery by WP Carousel < 2.5.3 - Contributor+ Stored XSS
The Carousel, Slider, Gallery by WP Carousel WordPress plugin before 2.5.3 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-4482?
CVE-2022-4482 has a medium severity rating due to its potential for Stored Cross-Site Scripting attacks.
How do I fix CVE-2022-4482?
To fix CVE-2022-4482, update the Carousel, Slider, Gallery by WP Carousel plugin to version 2.5.3 or later.
Who is affected by CVE-2022-4482?
Users with a role as low as contributor in WordPress can exploit CVE-2022-4482.
What kind of attacks can CVE-2022-4482 enable?
CVE-2022-4482 can enable Stored Cross-Site Scripting (XSS) attacks on vulnerable sites.
What versions of the plugin are vulnerable to CVE-2022-4482?
All versions of the Carousel, Slider, Gallery by WP Carousel plugin prior to 2.5.3 are vulnerable to CVE-2022-4482.