CVE-2022-4837: CPO Companion < 1.1.0 - Contributor+ Stored XSS via Shortcode
The CPO Companion WordPress plugin before 1.1.0 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-4837?
CVE-2022-4837 is classified as a medium severity vulnerability due to its potential for Stored Cross-Site Scripting attacks.
How do I fix CVE-2022-4837?
To fix CVE-2022-4837, update the CPO Companion WordPress plugin to version 1.1.0 or later.
What type of vulnerability is CVE-2022-4837?
CVE-2022-4837 is a Stored Cross-Site Scripting (XSS) vulnerability affecting the CPO Companion WordPress plugin.
Who is affected by CVE-2022-4837?
Users with a role as low as contributor can exploit CVE-2022-4837 due to insufficient validation of shortcode attributes.
Which plugin is vulnerable to CVE-2022-4837?
CVE-2022-4837 affects the CPO Companion WordPress plugin versions before 1.1.0.