CVE-2022-4484: Super Socializer < 7.13.44 - Contributor+ Stored XSS
The Social Share, Social Login and Social Comments Plugin WordPress plugin before 7.13.44 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-4484?
CVE-2022-4484 is a vulnerability in the Social Share, Social Login and Social Comments Plugin WordPress plugin before version 7.13.44 that allows users with a role as low as contributor to perform Stored Cross-Site Scripting (XSS) attacks.
What is the severity of CVE-2022-4484?
The severity of CVE-2022-4484 is medium, with a CVSS score of 5.4.
Which software version is affected by CVE-2022-4484?
The Social Share, Social Login and Social Comments Plugin WordPress plugin version up to exclusive 7.13.44 is affected by CVE-2022-4484.
How can the vulnerability CVE-2022-4484 be exploited?
CVE-2022-4484 can be exploited by users with a role as low as contributor who can inject malicious scripts through the plugin's shortcode attributes, leading to Stored Cross-Site Scripting attacks.
How can I fix CVE-2022-4484?
To fix CVE-2022-4484, it is recommended to update the Social Share, Social Login and Social Comments Plugin WordPress plugin to version 7.13.44 or later.