CVE-2022-4676: OSM – OpenStreetMap <= 6.01 - Contributor+ Stored XSS via Shortcode
The OSM WordPress plugin through 6.01 does not validate and escape some of its shortcode attributes, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attack.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this issue?
The vulnerability ID is CVE-2022-4676.
What is the severity level of CVE-2022-4676?
The severity level of CVE-2022-4676 is medium with a CVSS score of 5.4.
How does the OSM WordPress plugin through 6.01 expose this vulnerability?
The OSM WordPress plugin through 6.01 does not validate and escape some of its shortcode attributes, allowing users with low-level roles to perform a Stored Cross-Site Scripting attack.
Is there a fix available for CVE-2022-4676?
At the moment, there is no specific fix available. However, updating the OSM WordPress plugin to the latest version and maintaining a strong role-based access control can mitigate the risk.
Where can I find more information about CVE-2022-4676?
You can find more information about CVE-2022-4676 at the following reference: https://wpscan.com/vulnerability/1df3c17c-990d-4074-b1d5-b26da880d88e