CVE-2022-4789: WPZOOM Portfolio < 1.2.2 - Contributor+ Stored XSS via Shortcode
The WPZOOM Portfolio WordPress plugin before 1.2.2 does not validate and escape one of its shortcode attributes, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attack.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-4789?
CVE-2022-4789 is rated as a medium severity vulnerability due to the potential for Stored Cross-Site Scripting attacks.
How do I fix CVE-2022-4789?
To fix CVE-2022-4789, update the WPZOOM Portfolio WordPress plugin to version 1.2.2 or later.
Who is affected by CVE-2022-4789?
Any user with contributor role or higher can potentially exploit CVE-2022-4789 if they have access to the WPZOOM Portfolio plugin.
What types of attacks can CVE-2022-4789 facilitate?
CVE-2022-4789 can facilitate Stored Cross-Site Scripting attacks, which can lead to various security issues.
What versions of WPZOOM Portfolio are affected by CVE-2022-4789?
CVE-2022-4789 affects all versions of the WPZOOM Portfolio WordPress plugin prior to 1.2.2.