CVE-2022-4115
The Editorial Calendar WordPress plugin before 3.8.3 does not sanitise and escape its settings, allowing users with roles as low as contributor to inject arbitrary web scripts in the plugin admin panel, enabling a Stored Cross-Site Scripting…
Does this matter?
Lower severity and a low EPSS score (0.44%). Track it; it rarely justifies an emergency change on its own.
Description
The Editorial Calendar WordPress plugin before 3.8.3 does not sanitise and escape its settings, allowing users with roles as low as contributor to inject arbitrary web scripts in the plugin admin panel, enabling a Stored Cross-Site Scripting vulnerability targeting higher privileged users.
- CVSS 3.1
- 5.4 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 0.44% probability · 38th percentile
- CISA KEV
- Not listed
- Affected
- editorial calendar project/editorial calendar
- Source
- contact@wpscan.com
References
- https://wpscan.com/vulnerability/2b5071e1-9532-4a6c-9da4-d07932474ca4Exploit, Third Party Advisory
- https://wpscan.com/vulnerability/2b5071e1-9532-4a6c-9da4-d07932474ca4Exploit, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.