CVE-2022-4650: HashBar – WordPress Notification Bar < 1.3.6 - Contributor+ Stored XSS via Shortcode
Published Jan 23, 2023
·Updated
The HashBar WordPress plugin before 1.3.6 does not validate and escape one of its shortcode attributes, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attack.
Affected Software
1 affected component
HasThemes Hashbar Wordpress<1.3.6
Event History
Jan 23, 2023
CVE Published
via MITRE·02:31 PM
Data Sourced
via MITRE·02:31 PM
DescriptionWeakness
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2022-4650?
The severity of CVE-2022-4650 is medium with a CVSS score of 5.4.
2
How does CVE-2022-4650 affect the HashBar WordPress plugin?
CVE-2022-4650 affects the HashBar WordPress plugin before version 1.3.6.
3
What is the vulnerability type of CVE-2022-4650?
CVE-2022-4650 is a Stored Cross-Site Scripting (XSS) vulnerability.
4
What is the CWE identifier for CVE-2022-4650?
The CWE identifier for CVE-2022-4650 is CWE-79.
5
How can I fix the CVE-2022-4650 vulnerability in the HashBar WordPress plugin?
To fix the CVE-2022-4650 vulnerability, update the HashBar WordPress plugin to version 1.3.6 or above.