CVE-2022-2567
Last modified
CVE-2022-2567 is a medium-severity vulnerability rated 4.8/10 on the CVSS scale. The Form Builder CP WordPress plugin before 1.2.32 does not sanitise and escape some of its form settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). EPSS estimates a 0.49% chance of exploitation in the next 30 days.
Description
The Form Builder CP WordPress plugin before 1.2.32 does not sanitise and escape some of its form settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
Metrics
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Codepeople | Form Builder Cp | < 1.2.32 |
References
- https://wpscan.com/vulnerability/dfa21dde-a9fc-4a35-9602-c3fde907ca54Exploit, Patch, Third Party Advisory
- https://wpscan.com/vulnerability/dfa21dde-a9fc-4a35-9602-c3fde907ca54Exploit, Patch, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-2567?
How severe is CVE-2022-2567?
How do I fix CVE-2022-2567?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2022
- CVE-2022-25664Information disclosure due to exposure of information while …5.5
- CVE-2022-25665Information disclosure due to buffer over read in kernel in …7.1
- CVE-2022-25666Memory corruption due to use after free in service while try…6.7
- CVE-2022-25667Information disclosure in kernel due to improper handling of…7.5
- CVE-2022-25668Memory corruption in video driver due to double free while p…9.8
- CVE-2022-25669Denial of service in video due to buffer over read while par…7.5
- CVE-2022-25670Denial of service in WLAN HOST due to buffer over read while…7.5
- CVE-2022-25671Denial of service in MODEM due to reachable assertion in Sna…7.5
- CVE-2022-25672Denial of service in MODEM due to reachable assertion while …7.5
- CVE-2022-25673Denial of service in MODEM due to reachable assertion while …7.5
- CVE-2022-25674Cryptographic issues in WLAN during the group key handshake …9.8
- CVE-2022-25675Denial of service due to reachable assertion in modem while …5.5
Are you affected by CVE-2022-2567?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
