CVE-2022-4465
Last modified
CVE-2022-4465 is a medium-severity vulnerability rated 5.4/10 on the CVSS scale. The WP Video Lightbox WordPress plugin before 1.9.7 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admin.. EPSS estimates a 0.47% chance of exploitation in the next 30 days.
Description
The WP Video Lightbox WordPress plugin before 1.9.7 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admin.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Tipsandtricks-Hq | Wp Video Lightbox | < 1.9.7 |
References
- https://wpscan.com/vulnerability/28abe589-1371-4ed2-90b6-2bb96c93832cExploit, Third Party Advisory
- https://wpscan.com/vulnerability/28abe589-1371-4ed2-90b6-2bb96c93832cExploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-4465?
How severe is CVE-2022-4465?
How do I fix CVE-2022-4465?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2022
- CVE-2022-44644In Apache Linkis <=1.3.0 when used with the MySQL Connector/…6.5
- CVE-2022-44645In Apache Linkis <=1.3.0 when used with the MySQL Connector/…8.8
- CVE-2022-44646In JetBrains TeamCity version before 2022.10, no audit items…5.3
- CVE-2022-44647An Out-of-bounds read vulnerability in Trend Micro Apex One …5.5
- CVE-2022-44648An Out-of-bounds read vulnerability in Trend Micro Apex One …5.5
- CVE-2022-44649An out-of-bounds access vulnerability in the Unauthorized Ch…7.8
- CVE-2022-44650A memory corruption vulnerability in the Unauthorized Change…7.8
- CVE-2022-44651A Time-of-Check Time-Of-Use vulnerability in the Trend Micro…7
- CVE-2022-44652An improper handling of exceptional conditions vulnerability…7.8
- CVE-2022-44653A security agent directory traversal vulnerability in Trend …7.8
- CVE-2022-44654Affected builds of Trend Micro Apex One and Apex One as a Se…7.5
- CVE-2022-4466The WordPress Infinite Scroll WordPress plugin before 5.6.0.…5.4
Are you affected by CVE-2022-4465?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
