CVE-2022-4672: WordPress Simple Shopping Cart < 4.6.2 - Contributor+ Stored XSS via Shortcode
Published Jan 23, 2023
·Updated
The WordPress Simple Shopping Cart WordPress plugin before 4.6.2 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.
Affected Software
1 affected component
Tipsandtricks-hq Wordpress Simple Paypal Shopping Cart Wordpress<4.6.2
Event History
Jan 23, 2023
CVE Published
via MITRE·02:31 PM
Data Sourced
via MITRE·02:31 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID of this vulnerability?
The vulnerability ID is CVE-2022-4672.
2
What is the severity of CVE-2022-4672?
The severity of CVE-2022-4672 is medium (5.4).
3
Which WordPress plugin is affected by CVE-2022-4672?
The WordPress Simple Shopping Cart WordPress plugin before version 4.6.2 is affected by CVE-2022-4672.
4
What is the impact of CVE-2022-4672?
CVE-2022-4672 allows users with the role of contributor or lower to perform Stored Cross-Site Scripting attacks.
5
How can I fix CVE-2022-4672?
To fix CVE-2022-4672, update the WordPress Simple Shopping Cart WordPress plugin to version 4.6.2 or later.