CVE-2022-4699: MediaElement.js – HTML5 Video & Audio Player <= 4.2.8 - Contributor+ Stored XSS via Shortcode
The MediaElement.js WordPress plugin through 4.2.8 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high-privilege users such as admins.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-4699?
CVE-2022-4699 is a vulnerability in the MediaElement.js WordPress plugin through version 4.2.8 that allows stored cross-site scripting attacks.
How severe is CVE-2022-4699?
CVE-2022-4699 has a severity rating of medium, with a CVSS score of 5.4.
Which software versions are affected by CVE-2022-4699?
The MediaElement.js WordPress plugin version 4.2.8 and below are affected by CVE-2022-4699.
How can I fix CVE-2022-4699?
To fix CVE-2022-4699, update the MediaElement.js WordPress plugin to a version higher than 4.2.8.
Is there any additional information about CVE-2022-4699?
For more information about CVE-2022-4699, you can visit the reference link: https://wpscan.com/vulnerability/e57f38d9-889a-4f82-b20d-3676ccf9c6f9