CVE-2022-3132
MEDIUMCVSS 4.8/10EPSS 0.60%
Last modified
CVE-2022-3132 is a medium-severity vulnerability rated 4.8/10 on the CVSS scale. The Goolytics WordPress plugin before 1.1.2 does not sanitise and escape some of its settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.. EPSS estimates a 0.60% chance of exploitation in the next 30 days.
Description
The Goolytics WordPress plugin before 1.1.2 does not sanitise and escape some of its settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Goolytics Project | Goolytics | < 1.1.2 |
References
- https://wpscan.com/vulnerability/ed2dc1b9-f9f9-4e99-87b3-a614c223dd64Exploit, Third Party Advisory
- https://wpscan.com/vulnerability/ed2dc1b9-f9f9-4e99-87b3-a614c223dd64Exploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-3132?
The Goolytics WordPress plugin before 1.1.2 does not sanitise and escape some of its settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.
How severe is CVE-2022-3132?
CVE-2022-3132 has a CVSS score of 4.8/10 (MEDIUM severity). The EPSS model estimates a 0.60% probability of exploitation in the next 30 days.
How do I fix CVE-2022-3132?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2022
- CVE-2022-31307Nginx NJS v0.7.2 was discovered to contain a segmentation vi…5.5
- CVE-2022-31308A vulnerability in live_mfg.shtml of WAVLINK AERIAL X 1200M …7.5
- CVE-2022-31309A vulnerability in live_check.shtml of WAVLINK AERIAL X 1200…7.5
- CVE-2022-3131The Search Logger WordPress plugin through 0.9 does not prop…7.2
- CVE-2022-31311An issue in adm.cgi of WAVLINK AERIAL X 1200M M79X3.V5030.18…9.8
- CVE-2022-31313api-res-py package in PyPI 0.1 is vulnerable to a code execu…9.8
- CVE-2022-31321The foldername parameter in Bolt 5.1.7 was discovered to hav…9.1
- CVE-2022-31322Penta Security Systems Inc WAPPLES v6.0 r3 4.10-hotfix1 allo…7.8
- CVE-2022-31324An arbitrary file download vulnerability in the downloadActi…6.5
- CVE-2022-31325There is a SQL Injection vulnerability in ChurchCRM 4.4.5 vi…7.2
- CVE-2022-31327Online Ordering System By janobe 2.3.2 is vulneranle to SQL …9.8
- CVE-2022-31328Online Ordering System By janobe 2.3.2 has SQL Injection via…9.8
Are you affected by CVE-2022-3132?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
