WP Total Hacks <= 4.7.2 - Subscriber+ Arbitrary Options Update to Stored XSS
CVE-2022-3096
5.4MEDIUM
What is CVE-2022-3096?
The WP Total Hacks WordPress plugin through 4.7.2 does not prevent low privilege users from modifying the plugin's settings. This could allow users such as subscribers to perform Stored Cross-Site Scripting attacks against other users, like administrators, due to the lack of sanitisation and escaping as well.
Affected Version(s)
WP Total Hacks 4.7.2