CVE-2022-50797: Stripe Green Downloads Wordpress Plugin 2.03 Persistent XSS via Settings
Stripe Green Downloads Wordpress Plugin 2.03 contains a persistent cross-site scripting vulnerability allowing remote attackers to inject malicious scripts in button label fields. Attackers can exploit input parameters to execute arbitrary scripts, potentially leading to session hijacking and application module manipulation.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-50797?
CVE-2022-50797 is classified as a high severity vulnerability due to its potential for persistent cross-site scripting attacks.
How do I fix CVE-2022-50797?
To mitigate CVE-2022-50797, update the Stripe Green Downloads WordPress Plugin to the latest version or apply patches as recommended by the vendor.
What type of vulnerability is CVE-2022-50797?
CVE-2022-50797 is a persistent cross-site scripting (XSS) vulnerability that allows attackers to inject malicious scripts.
Who is affected by CVE-2022-50797?
Users of Stripe Green Downloads WordPress Plugin version 2.03 are primarily affected by CVE-2022-50797.
What can be the impact of CVE-2022-50797?
CVE-2022-50797 can lead to unauthorized script execution and data theft if exploited successfully.