CVE-2022-4836: Breadcrumb < 1.5.33 - Contributor+ Stored XSS via Shortcode
The Breadcrumb WordPress plugin before 1.5.33 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of the Breadcrumb WordPress plugin vulnerability?
The vulnerability ID of the Breadcrumb WordPress plugin vulnerability is CVE-2022-4836.
What is the severity rating of the Breadcrumb WordPress plugin vulnerability?
The severity rating of the Breadcrumb WordPress plugin vulnerability is medium (5.4).
What is the affected software version of the Breadcrumb WordPress plugin vulnerability?
The affected software version of the Breadcrumb WordPress plugin vulnerability is before 1.5.33.
How can a user exploit the Breadcrumb WordPress plugin vulnerability?
A user with a role as low as contributor can exploit the Breadcrumb WordPress plugin vulnerability to perform Stored Cross-Site Scripting attacks.
Is there a fix available for the Breadcrumb WordPress plugin vulnerability?
Yes, a fix is available for the Breadcrumb WordPress plugin vulnerability. Update to version 1.5.33 or later.