CVE-2022-1027
Last modified
CVE-2022-1027 is a medium-severity vulnerability rated 4.8/10 on the CVSS scale. The Page Restriction WordPress (WP) WordPress plugin before 1.2.7 allows bad actors with administrator privileges to the settings page to inject Javascript code to its settings leading to stored Cross-Site Scripting that will only affect administrator users.. EPSS estimates a 0.58% chance of exploitation in the next 30 days.
Description
The Page Restriction WordPress (WP) WordPress plugin before 1.2.7 allows bad actors with administrator privileges to the settings page to inject Javascript code to its settings leading to stored Cross-Site Scripting that will only affect administrator users.
Metrics
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Minioragne | Page Restriction | < 1.2.7 |
References
- https://wpscan.com/vulnerability/9dbb0d6d-bc84-4b85-8aa5-fa2a8e6fa5e3Exploit, Third Party Advisory
- https://wpscan.com/vulnerability/9dbb0d6d-bc84-4b85-8aa5-fa2a8e6fa5e3Exploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-1027?
How severe is CVE-2022-1027?
How do I fix CVE-2022-1027?
Are you affected by CVE-2022-1027?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
