CVE-2022-4946: Frontend Post WordPress Plugin <= 2.8.4 - Contributor+ Arbitrary Redirect
The Frontend Post WordPress Plugin WordPress plugin through 2.8.4 does not validate an attribute of one of its shortcode, which could allow users with a role as low as contributor to add a malicious shortcode to a page/post, which will redirect users to an arbitrary domain.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-4946?
CVE-2022-4946 is a vulnerability in the Frontend Post WordPress Plugin version up to 2.8.4 that allows users with low privilege levels to add a malicious shortcode to a page or post, resulting in a redirect to an arbitrary domain.
How severe is CVE-2022-4946?
CVE-2022-4946 has a severity keyword of 'medium' and a severity value of 5.4.
Which software is affected by CVE-2022-4946?
The Frontend Post WordPress Plugin version up to 2.8.4 is affected by CVE-2022-4946.
How can the vulnerability in CVE-2022-4946 be exploited?
Exploiting CVE-2022-4946 involves adding a malicious shortcode to a page or post using the vulnerable Frontend Post WordPress Plugin, which then redirects users to an arbitrary domain.
Is there a fix available for CVE-2022-4946?
At the time of writing, there is no known fix available for CVE-2022-4946. It is recommended to update to the latest version of the Frontend Post WordPress Plugin and to review and remove any potentially malicious shortcodes.