CVE-2022-4653: Greenshift – animation and page builder blocks < 4.8.9 - Contributor+ Stored XSS via Shortcode
Published Jan 16, 2023
·Updated
The Greenshift WordPress plugin before 4.8.9 does not validate and escape one of its shortcode attributes, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attack.
Affected Software
2 affected components
Greenshiftwp Greenshift - Animation And Page Builder Blocks Wordpress<4.8.9
Wpsoul Greenshift Wordpress<4.8.9
Event History
Jan 16, 2023
CVE Published
via MITRE·03:37 PM
Data Sourced
via MITRE·03:37 PM
DescriptionWeakness
Data Sourced
via NVD·04:15 PM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is CVE-2022-4653?
CVE-2022-4653 is a vulnerability in the Greenshift WordPress plugin before version 4.8.9.
2
What is the severity of CVE-2022-4653?
CVE-2022-4653 has a severity rating of medium with a CVSS score of 5.4.
3
How does CVE-2022-4653 affect the Greenshift WordPress plugin?
CVE-2022-4653 affects the Greenshift WordPress plugin version before 4.8.9.
4
What is the affected software for CVE-2022-4653?
The affected software for CVE-2022-4653 is Greenshift - Animation And Page Builder Blocks plugin for WordPress before version 4.8.9.
5
How can I fix CVE-2022-4653?
To fix CVE-2022-4653, update the Greenshift WordPress plugin to version 4.8.9 or higher.