CVE-2022-4509: Content Control < 1.1.10 - Contributor+ Stored XSS
The Content Control WordPress plugin before 1.1.10 does not validate and escapes some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as a contributor to perform Stored Cross-Site Scripting attacks, which could be used against high privilege users such as admins.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2022-4509.
What is the severity rating of CVE-2022-4509?
CVE-2022-4509 has a severity rating of medium (5.4).
What is the affected software?
The affected software is the Content Control WordPress plugin before version 1.1.10.
What is the potential risk of this vulnerability?
The potential risk of CVE-2022-4509 is that users with a role as low as a contributor could perform Stored Cross-Site Scripting attacks.
Is there a fix available for CVE-2022-4509?
Yes, the fix for CVE-2022-4509 is to update the Content Control WordPress plugin to version 1.1.10 or higher.