CVE-2022-4830: Paid Memberships Pro < 2.9.9 - Contributor+ Stored XSS via Shortcode
The Paid Memberships Pro WordPress plugin before 2.9.9 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for Paid Memberships Pro WordPress plugin?
The vulnerability ID for Paid Memberships Pro WordPress plugin is CVE-2022-4830.
What is the severity of the vulnerability CVE-2022-4830?
The severity of the vulnerability CVE-2022-4830 is medium with a severity value of 5.4.
What is the affected software for the vulnerability CVE-2022-4830?
The affected software for the vulnerability CVE-2022-4830 is the Paid Memberships Pro WordPress plugin before version 2.9.9.
What is the CWE category for the vulnerability CVE-2022-4830?
The CWE category for the vulnerability CVE-2022-4830 is CWE-79.
How can I mitigate the vulnerability CVE-2022-4830?
To mitigate the vulnerability CVE-2022-4830, it is recommended to update the Paid Memberships Pro WordPress plugin to version 2.9.9 or higher.