First published: Mon Jan 23 2023(Updated: )
The WordPress Simple Shopping Cart WordPress plugin before 4.6.2 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
Tipsandtricks-hq Wordpress Simple Paypal Shopping Cart | <4.6.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2022-4672.
The severity of CVE-2022-4672 is medium (5.4).
The WordPress Simple Shopping Cart WordPress plugin before version 4.6.2 is affected by CVE-2022-4672.
CVE-2022-4672 allows users with the role of contributor or lower to perform Stored Cross-Site Scripting attacks.
To fix CVE-2022-4672, update the WordPress Simple Shopping Cart WordPress plugin to version 4.6.2 or later.