CVE-2022-4623: ND Shortcodes < 7.0 - Contributor+ Stored XSS via Shortcodes
Published Jul 4, 2023
·Updated
The ND Shortcodes WordPress plugin before 7.0 does not validate and escape numerous of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks
Affected Software
1 affected component
Nicdark Nd Shortcodes Wordpress<7.0
Event History
Jul 4, 2023
CVE Published
via MITRE·07:23 AM
Data Sourced
via MITRE·07:23 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2022-4623.
2
What is the severity of CVE-2022-4623?
The severity of CVE-2022-4623 is medium with a CVSS score of 5.4.
3
What is the affected software?
The affected software is the ND Shortcodes WordPress plugin version up to 7.0.
4
What is the impact of CVE-2022-4623?
CVE-2022-4623 allows users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
5
How do I fix CVE-2022-4623?
To fix CVE-2022-4623, update the ND Shortcodes WordPress plugin to version 7.0 or above.