Lucene search

K
cveWPScanCVE-2022-2171
HistoryAug 01, 2022 - 1:15 p.m.

CVE-2022-2171

2022-08-0113:15:10
CWE-352
WPScan
web.nvd.nist.gov
43
7
progressive license
wordpress plugin
csrf
admin
stored xss
nvd

CVSS3

5.4

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

EPSS

0.001

Percentile

21.2%

The Progressive License WordPress plugin through 1.1.0 is lacking any CSRF check when saving its settings, which could allow attackers to make a logged in admin change them. Furthermore, as the plugin allows arbitrary HTML to be inserted in one of the settings, this could lead to Stored XSS issue which will be triggered in the frontend as well.

Affected configurations

Nvd
Vulners
Node
crowdfavoriteprogressive_licenseRange1.1.0wordpress
VendorProductVersionCPE
crowdfavoriteprogressive_license*cpe:2.3:a:crowdfavorite:progressive_license:*:*:*:*:*:wordpress:*:*

CNA Affected

[
  {
    "product": "Progressive License",
    "vendor": "Unknown",
    "versions": [
      {
        "lessThanOrEqual": "1.1.0",
        "status": "affected",
        "version": "1.1.0",
        "versionType": "custom"
      }
    ]
  }
]

Social References

More

CVSS3

5.4

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

EPSS

0.001

Percentile

21.2%

Related for CVE-2022-2171