CVE-2022-45825: WordPress WPComplete Plugin <= 2.9.4 is vulnerable to Cross Site Scripting (XSS)
Published Mar 28, 2023
·Updated
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in iThemes WPComplete plugin <= 2.9.2 versions.
Affected Software
1 affected component
Liquidweb Wpcomplete Wordpress<2.9.5
Remediation
Information
Update to 2.9.5 or a higher version.
Event History
Mar 28, 2023
CVE Published
via MITRE·07:04 AM
Data Sourced
via MITRE·07:04 AM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2022-45825.
2
What is the title of the vulnerability?
The title of the vulnerability is 'Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in iThemes WPComplete plugin <= 2.9.2 ver…'
3
What is the severity of CVE-2022-45825?
The severity of CVE-2022-45825 is high with a severity value of 6.1.
4
Which software versions are affected by CVE-2022-45825?
The iThemes WPComplete plugin versions <= 2.9.2 are affected by CVE-2022-45825.
5
Is there a fix available for CVE-2022-45825?
Yes, a fix is available for CVE-2022-45825. It is recommended to update to version 2.9.5 or newer of the iThemes WPComplete plugin.