CVE-2022-4759: GigPress < 2.3.28 - Contributor+ Stored XSS via Shortcode
The GigPress WordPress plugin before 2.3.28 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-4759?
CVE-2022-4759 is a vulnerability in the GigPress WordPress plugin before version 2.3.28 that allows users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
What is the severity of CVE-2022-4759?
CVE-2022-4759 has a severity rating of Medium, with a CVSS score of 5.4.
How does CVE-2022-4759 affect the GigPress plugin?
CVE-2022-4759 affects the GigPress WordPress plugin before version 2.3.28 by allowing users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
How do I fix CVE-2022-4759?
To fix CVE-2022-4759, update the GigPress plugin to version 2.3.28 or newer.
What is Stored Cross-Site Scripting (XSS) attack?
Stored Cross-Site Scripting (XSS) attack is a type of vulnerability where malicious scripts are injected into a website and then executed by users who visit the compromised page.