CVE-2022-3609
Last modified
CVE-2022-3609 is a medium-severity vulnerability rated 4.8/10 on the CVSS scale. The GetYourGuide Ticketing WordPress plugin before 1.0.4 does not sanitise and escape some parameters, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). EPSS estimates a 0.39% chance of exploitation in the next 30 days.
Description
The GetYourGuide Ticketing WordPress plugin before 1.0.4 does not sanitise and escape some parameters, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
Metrics
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Getyourguide Ticketing Project | Getyourguide Ticketing | < 1.0.4 |
References
- https://wpscan.com/vulnerability/b893cac2-6511-4e2a-9eff-baf0f3cc9d7eThird Party Advisory
- https://wpscan.com/vulnerability/b893cac2-6511-4e2a-9eff-baf0f3cc9d7eThird Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-3609?
How severe is CVE-2022-3609?
How do I fix CVE-2022-3609?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2022
- CVE-2022-36084cruddl is software for creating a GraphQL API for a database…8.8
- CVE-2022-36085Open Policy Agent (OPA) is an open source, general-purpose p…9.8
- CVE-2022-36086linked_list_allocator is an allocator usable for no_std syst…9.8
- CVE-2022-36087OAuthLib is an implementation of the OAuth request-signing l…6.5
- CVE-2022-36088GoCD is a continuous delivery server. Windows installations …5.5
- CVE-2022-36089KubeVela is an application delivery platform Users using Kub…9.8
- CVE-2022-36090XWiki Platform Old Core is a core package for XWiki Platform…8.1
- CVE-2022-36091XWiki Platform Web Templates are templates for XWiki Platfor…7.5
- CVE-2022-36092XWiki Platform Old Core is a core package for XWiki Platform…7.5
- CVE-2022-36093XWiki Platform Web Templates are templates for XWiki Platfor…7.1
- CVE-2022-36094XWiki Platform Web Parent POM contains Web resources for the…9
- CVE-2022-36095XWiki Platform is a generic wiki platform. Prior to versions…4.3
Are you affected by CVE-2022-3609?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
