CVE-2022-3440
Last modified
CVE-2022-3440 is a medium-severity vulnerability rated 6.1/10 on the CVSS scale. The Rock Convert WordPress plugin before 2.11.0 does not sanitise and escape an URL before outputting it back in an attribute when a specific widget is present on a page, leading to a Reflected Cross-Site Scripting. EPSS estimates a 0.49% chance of exploitation in the next 30 days.
Description
The Rock Convert WordPress plugin before 2.11.0 does not sanitise and escape an URL before outputting it back in an attribute when a specific widget is present on a page, leading to a Reflected Cross-Site Scripting
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Rockcontent | Rock Convert | < 2.11.0 |
References
- https://wpscan.com/vulnerability/e39fcf30-1e69-4399-854c-4c5b6ccc22a2Exploit, Third Party Advisory
- https://wpscan.com/vulnerability/e39fcf30-1e69-4399-854c-4c5b6ccc22a2Exploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-3440?
How severe is CVE-2022-3440?
How do I fix CVE-2022-3440?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2022
- CVE-2022-34394Dell OS10, version 10.5.3.4, contains an Improper Certificat…3.7
- CVE-2022-34395Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2022-34396 Dell OpenManage Server Administrator (OMSA) version 10.3.0.…7.8
- CVE-2022-34397 Dell Unisphere for PowerMax vApp, VASA Provider vApp, and S…5.7
- CVE-2022-34398 Dell BIOS contains a Time-of-check Time-of-use vulnerabilit…7
- CVE-2022-34399 Dell Alienware m17 R5 BIOS version prior to 1.2.2 contain a…2.3
- CVE-2022-34400 Dell BIOS contains a heap buffer overflow vulnerability. A …7.1
- CVE-2022-34401 Dell BIOS contains a stack based buffer overflow vulnerabil…7.5
- CVE-2022-34402Dell Wyse ThinOS 2205 contains a Regular Expression Denial o…4.9
- CVE-2022-34403 Dell BIOS contains a Stack based buffer overflow vulnerabil…8.8
- CVE-2022-34404 Dell System Update, version 2.0.0 and earlier, contains an …6
- CVE-2022-34405An improper access control vulnerability was identified in t…7.3
Are you affected by CVE-2022-3440?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
