WP Total Hacks <= 4.7.2 - Subscriber+ Arbitrary Options Update to Stored XSS
CVE-2022-3096

5.4MEDIUM

Key Information:

Vendor
Wordpress
Vendor
CVE Published:
31 October 2022

Summary

The WP Total Hacks WordPress plugin through 4.7.2 does not prevent low privilege users from modifying the plugin's settings. This could allow users such as subscribers to perform Stored Cross-Site Scripting attacks against other users, like administrators, due to the lack of sanitisation and escaping as well.

Affected Version(s)

WP Total Hacks 4.7.2

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Daniel Ruf
.