SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2022-1772

A malicious administrator could abuse this bug, in a multisite WordPress configuration, to trick super-administrators into viewing the booby-trapped payload and taking over their account.

MEDIUM 4.8EPSS 0.75%

Does this matter?

Lower severity and a low EPSS score (0.75%). Track it; it rarely justifies an emergency change on its own.

Description

The Google Places Reviews WordPress plugin before 2.0.0 does not properly escape its Google API key setting, which is reflected on the site's administration panel. A malicious administrator could abuse this bug, in a multisite WordPress configuration, to trick super-administrators into viewing the booby-trapped payload and taking over their account.

CVSS 3.1
4.8 MEDIUMCVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
EPSS
0.75% probability · 53th percentile
CISA KEV
Not listed
Weakness
CWE-79
Affected
google places reviews project/google places reviews
Source
contact@wpscan.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.