CVE-2022-3132
Last modified
CVE-2022-3132 is a medium-severity vulnerability rated 4.8/10 on the CVSS scale. The Goolytics WordPress plugin before 1.1.2 does not sanitise and escape some of its settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.. EPSS estimates a 0.60% chance of exploitation in the next 30 days.
Description
The Goolytics WordPress plugin before 1.1.2 does not sanitise and escape some of its settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.
Metrics
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Goolytics Project | Goolytics | < 1.1.2 |
References
- https://wpscan.com/vulnerability/ed2dc1b9-f9f9-4e99-87b3-a614c223dd64Exploit, Third Party Advisory
- https://wpscan.com/vulnerability/ed2dc1b9-f9f9-4e99-87b3-a614c223dd64Exploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-3132?
How severe is CVE-2022-3132?
How do I fix CVE-2022-3132?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2022
- CVE-2022-31307Nginx NJS v0.7.2 was discovered to contain a segmentation vi…5.5
- CVE-2022-31308A vulnerability in live_mfg.shtml of WAVLINK AERIAL X 1200M …7.5
- CVE-2022-31309A vulnerability in live_check.shtml of WAVLINK AERIAL X 1200…7.5
- CVE-2022-3131The Search Logger WordPress plugin through 0.9 does not prop…7.2
- CVE-2022-31311An issue in adm.cgi of WAVLINK AERIAL X 1200M M79X3.V5030.18…9.8
- CVE-2022-31313api-res-py package in PyPI 0.1 is vulnerable to a code execu…9.8
- CVE-2022-31321The foldername parameter in Bolt 5.1.7 was discovered to hav…9.1
- CVE-2022-31322Penta Security Systems Inc WAPPLES v6.0 r3 4.10-hotfix1 allo…7.8
- CVE-2022-31324An arbitrary file download vulnerability in the downloadActi…6.5
- CVE-2022-31325There is a SQL Injection vulnerability in ChurchCRM 4.4.5 vi…7.2
- CVE-2022-31327Online Ordering System By janobe 2.3.2 is vulneranle to SQL …9.8
- CVE-2022-31328Online Ordering System By janobe 2.3.2 has SQL Injection via…9.8
Are you affected by CVE-2022-3132?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
