CVE-2022-2543
Last modified
CVE-2022-2543 is a medium-severity vulnerability rated 6.1/10 on the CVSS scale. The Visual Portfolio, Photo Gallery & Post Grid WordPress plugin before 2.18.0 does not have proper authorisation checks in some of its REST endpoints, allowing unauthenticated users to call them and inject arbitrary CSS in arbitrary saved layouts. EPSS estimates a 0.48% chance of exploitation in the next 30 days.
Description
The Visual Portfolio, Photo Gallery & Post Grid WordPress plugin before 2.18.0 does not have proper authorisation checks in some of its REST endpoints, allowing unauthenticated users to call them and inject arbitrary CSS in arbitrary saved layouts
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Visualportfolio | Visual Portfolio\, Photo Gallery \& Post Grid | < 2.18.0 |
References
- https://wpscan.com/vulnerability/5dc8b671-f2fa-47be-8664-9005c4fdbea8Exploit, Third Party Advisory
- https://wpscan.com/vulnerability/5dc8b671-f2fa-47be-8664-9005c4fdbea8Exploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-2543?
How severe is CVE-2022-2543?
How do I fix CVE-2022-2543?
Are you affected by CVE-2022-2543?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
