CVE-2022-0989
Last modified
CVE-2022-0989 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. An unprivileged user could use the functionality of the NS WooCommerce Watermark WordPress plugin through 2.11.3 to load images that hide malware for example from passing malicious domains to hide their trace, by making them pass through the vulnerable domain.. EPSS estimates a 1.19% chance of exploitation in the next 30 days.
Description
An unprivileged user could use the functionality of the NS WooCommerce Watermark WordPress plugin through 2.11.3 to load images that hide malware for example from passing malicious domains to hide their trace, by making them pass through the vulnerable domain.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Nsthemes | Ns Watermark For Woocommerce | <= 2.11.3 |
References
- https://wpscan.com/vulnerability/a6bfc150-8e3f-4b2d-a6e1-09406af41dd4Exploit, Third Party Advisory
- https://wpscan.com/vulnerability/a6bfc150-8e3f-4b2d-a6e1-09406af41dd4Exploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-0989?
How severe is CVE-2022-0989?
How do I fix CVE-2022-0989?
Are you affected by CVE-2022-0989?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
