CVE | CVE-2022-4760 |
CVE Title | |
Published Date | 2023-01-23T15:15Z |
Modified Date | 2023-01-23T17:17Z |
CWE Type | CWE-79 |
Description | The OneClick Chat to Order WordPress plugin before 1.0.4.2 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins. |
References | |
By clicking these links you will leave this website. We do not endorse and will not be held accountable for any activity on external sites. | |
Reference URL | https://wpscan.com/vulnerability/ad710c22-878a-441b-9c5a-90511b913d9d |
Reference Description | MISC https://wpscan.com/vulnerability/ad710c22-878a-441b-9c5a-90511b913d9d |
Reference Description | |
Sources | NIST MITRE |
Note
- No CVSS data for this CVE