CVE-2022-3096
Last modified
CVE-2022-3096 is a medium-severity vulnerability rated 5.4/10 on the CVSS scale. The WP Total Hacks WordPress plugin through 4.7.2 does not prevent low privilege users from modifying the plugin's settings. This could allow users such as subscribers to perform Stored Cross-Site Scripting attacks against other users, like administrators, due to the lack of sanitisation and escaping as well.. EPSS estimates a 0.41% chance of exploitation in the next 30 days.
Description
The WP Total Hacks WordPress plugin through 4.7.2 does not prevent low privilege users from modifying the plugin's settings. This could allow users such as subscribers to perform Stored Cross-Site Scripting attacks against other users, like administrators, due to the lack of sanitisation and escaping as well.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Wp Total Hacks Project | Wp Total Hacks | <= 4.7.2 |
References
- https://wpscan.com/vulnerability/46996537-a874-4b2e-9cd7-7d0832f9704dExploit, Third Party Advisory
- https://wpscan.com/vulnerability/46996537-a874-4b2e-9cd7-7d0832f9704dExploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-3096?
How severe is CVE-2022-3096?
How do I fix CVE-2022-3096?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2022
- CVE-2022-30954Jenkins Blue Ocean Plugin 1.25.3 and earlier does not perfor…6.5
- CVE-2022-30955Jenkins GitLab Plugin 1.5.31 and earlier does not perform a …6.5
- CVE-2022-30956Jenkins Rundeck Plugin 3.6.10 and earlier does not restrict …5.4
- CVE-2022-30957A missing permission check in Jenkins SSH Plugin 2.6.1 and e…4.3
- CVE-2022-30958A cross-site request forgery (CSRF) vulnerability in Jenkins…8.8
- CVE-2022-30959A missing permission check in Jenkins SSH Plugin 2.6.1 and e…6.5
- CVE-2022-30960Jenkins Application Detector Plugin 1.0.8 and earlier does n…5.4
- CVE-2022-30961Jenkins Autocomplete Parameter Plugin 1.1 and earlier does n…5.4
- CVE-2022-30962Jenkins Global Variable String Parameter Plugin 1.2 and earl…5.4
- CVE-2022-30963Jenkins JDK Parameter Plugin 1.0 and earlier does not escape…5.4
- CVE-2022-30964Jenkins Multiselect parameter Plugin 1.3 and earlier does no…5.4
- CVE-2022-30965Jenkins Promoted Builds (Simple) Plugin 1.9 and earlier does…5.4
Are you affected by CVE-2022-3096?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
