CVE-2022-4330
Last modified
CVE-2022-4330 is a medium-severity vulnerability rated 4.8/10 on the CVSS scale. The WP Attachments WordPress plugin before 5.0.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).. EPSS estimates a 0.47% chance of exploitation in the next 30 days.
Description
The WP Attachments WordPress plugin before 5.0.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
Metrics
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Marcomilesi | Wp Attachments | < 5.0.6 |
References
- https://wpscan.com/vulnerability/d3c39e17-1dc3-4275-97d8-543ca7226772Exploit, Third Party Advisory
- https://wpscan.com/vulnerability/d3c39e17-1dc3-4275-97d8-543ca7226772Exploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-4330?
How severe is CVE-2022-4330?
How do I fix CVE-2022-4330?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2022
- CVE-2022-43290Canteen Management System v1.0 was discovered to contain a S…7.2
- CVE-2022-43291Canteen Management System v1.0 was discovered to contain a S…7.2
- CVE-2022-43292Canteen Management System v1.0 was discovered to contain a S…7.2
- CVE-2022-43293Wacom Driver 6.3.46-1 for Windows was discovered to contain …5.9
- CVE-2022-43294Tasmota before commit 066878da4d4762a9b6cb169fdf353e804d735c…9.8
- CVE-2022-43295XPDF v4.04 was discovered to contain a stack overflow via th…5.5
- CVE-2022-43303The d8s-strings for python, as distributed on PyPI, included…9.8
- CVE-2022-43304The d8s-timer for python, as distributed on PyPI, included a…9.8
- CVE-2022-43305The d8s-python for python, as distributed on PyPI, included …9.8
- CVE-2022-43306The d8s-timer for python, as distributed on PyPI, included a…8.8
- CVE-2022-43308INTELBRAS SG 2404 MR 20180928-rel64938 allows authenticated …7.8
- CVE-2022-43309Supermicro X11SSL-CF HW Rev 1.01, BMC firmware v1.63 was dis…5.5
Are you affected by CVE-2022-4330?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
