CVE-2022-4464

Themify Portfolio Post WordPress plugin before 1.2.1 does not validate and escapes some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as a contributor to perform Stored Cross-Site Scripting attacks, which could be used against high privileged users such as admin.
Configurations

Configuration 1 (hide)

cpe:2.3:a:themify:portfolio_post:*:*:*:*:*:wordpress:*:*

History

21 Nov 2024, 07:35

Type Values Removed Values Added
Summary
  • (es) El complemento Themify Portfolio Post de WordPress, en sus versiones anteriores a la 1.2.1, no valida ni escapa algunos de sus atributos antes de devolverlos a la página, lo que podría permitir a los usuarios con un rol tan bajo como el de colaborador realizar ataques de cross site scripting almacenado, lo que podría utilizarse contra usuarios con privilegios elevados, como el administrador.
References () https://wpscan.com/vulnerability/1d3636c1-976f-4c84-8cca-413e38170d0c - Exploit, Third Party Advisory () https://wpscan.com/vulnerability/1d3636c1-976f-4c84-8cca-413e38170d0c - Exploit, Third Party Advisory

Information

Published : 2023-01-16 16:15

Updated : 2025-04-08 20:15


NVD link : CVE-2022-4464

Mitre link : CVE-2022-4464

CVE.ORG link : CVE-2022-4464


JSON object : View

Products Affected

themify

  • portfolio_post
CWE

No CWE.