CVE-2022-4758: 10WebMapBuilder < 1.0.72 - Contributor+ Stored XSS via Shortcode
The 10WebMapBuilder WordPress plugin before 1.0.72 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.
Affected Software
Event History
Frequently Asked Questions
What is vulnerability CVE-2022-4758?
Vulnerability CVE-2022-4758 is a Stored Cross-Site Scripting (XSS) vulnerability in the 10WebMapBuilder WordPress plugin before version 1.0.72.
What is the severity of vulnerability CVE-2022-4758?
Vulnerability CVE-2022-4758 has a severity score of 5.4, which is considered medium.
Which software is affected by vulnerability CVE-2022-4758?
The 10WebMapBuilder WordPress plugin before version 1.0.72 is affected by vulnerability CVE-2022-4758.
How can the vulnerability CVE-2022-4758 be exploited?
The vulnerability CVE-2022-4758 can be exploited by users with a role as low as contributor to perform Stored Cross-Site Scripting (XSS) attacks.
How can I fix vulnerability CVE-2022-4758 in the 10WebMapBuilder WordPress plugin?
To fix vulnerability CVE-2022-4758, update the 10WebMapBuilder WordPress plugin to version 1.0.72 or higher.