CVE-2022-1418
Last modified
CVE-2022-1418 is a medium-severity vulnerability rated 6.1/10 on the CVSS scale. The Social Stickers WordPress plugin through 2.2.9 does not have CSRF checks in place when updating its Social Network settings, and does not escape some of these fields, which could allow attackers to make a logged-in admin change them and lead to Stored Cross-Site Scripting issues.. EPSS estimates a 0.38% chance of exploitation in the next 30 days.
Description
The Social Stickers WordPress plugin through 2.2.9 does not have CSRF checks in place when updating its Social Network settings, and does not escape some of these fields, which could allow attackers to make a logged-in admin change them and lead to Stored Cross-Site Scripting issues.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Pluginmirror | Social Stickers | <= 2.2.9 |
References
- https://wpscan.com/vulnerability/3851e61e-f462-4259-af0a-8d832809d559Exploit, Third Party Advisory
- https://wpscan.com/vulnerability/3851e61e-f462-4259-af0a-8d832809d559Exploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-1418?
How severe is CVE-2022-1418?
How do I fix CVE-2022-1418?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2022
- CVE-2022-1412The Log WP_Mail WordPress plugin through 0.1 saves sent emai…7.5
- CVE-2022-1413Missing input masking in GitLab CE/EE affecting all versions…7.5
- CVE-2022-14143scale API Management 2 does not perform adequate sanitation…8.8
- CVE-2022-1415A flaw was found where some utility classes in Drools core d…8.8
- CVE-2022-1416Missing sanitization of data in Pipeline error messages in G…5.4
- CVE-2022-1417Improper access control in GitLab CE/EE affecting all versio…4.3
- CVE-2022-1419The root cause of this vulnerability is that the ioctl$DRM_I…7.8
- CVE-2022-1420Use of Out-of-range Pointer Offset in GitHub repository vim/…5.5
- CVE-2022-1421The Discy WordPress theme before 5.2 lacks CSRF checks in so…4.3
- CVE-2022-1422The Discy WordPress theme before 5.2 does not check for CSRF…6.5
- CVE-2022-1423Improper access control in the CI/CD cache mechanism in GitL…8.8
- CVE-2022-1424The Ask me WordPress theme before 6.8.2 does not perform CSR…6.5
Are you affected by CVE-2022-1418?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
