CVE-2022-4763: Icon Widget < 1.3.0 - Contributor+ Stored XSS via Shortcode
The Icon Widget WordPress plugin before 1.3.0 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-4763?
CVE-2022-4763 has a medium severity rating due to its potential for Stored Cross-Site Scripting attacks.
How do I fix CVE-2022-4763?
To fix CVE-2022-4763, update the Icon Widget WordPress plugin to version 1.3.0 or later.
Who is affected by CVE-2022-4763?
Users with a role as low as contributor can be affected by CVE-2022-4763, allowing them to execute attacks.
What type of vulnerability is CVE-2022-4763?
CVE-2022-4763 is categorized as a Stored Cross-Site Scripting vulnerability.
When was CVE-2022-4763 identified?
CVE-2022-4763 was identified before version 1.3.0 of the Icon Widget WordPress plugin.