Reflected Cross-Site Scripting Vulnerability in Invitation Code Content Restriction Plugin
CVE-2022-4965

6.1MEDIUM

What is CVE-2022-4965?

The Invitation Code Content Restriction Plugin offered by CreativeMinds for WordPress exposes a vulnerability that could be exploited through Reflected Cross-Site Scripting (XSS). This vulnerability arises from inadequate input sanitization and output escaping, particularly concerning the 'target_id' parameter. Attackers who are unauthenticated can leverage this flaw to inject arbitrary web scripts into web pages. The execution of these scripts occurs when users are manipulated into performing specific actions, such as clicking on an affected link, potentially compromising the security of user sessions and site integrity.

Affected Version(s)

Invitation Code Content Restriction Plugin from CreativeMinds * <= 1.5.4

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Paolo CavagliĂ 
.