Lucene search

K
cvePatchstackCVE-2022-40195
HistorySep 23, 2022 - 3:15 p.m.

CVE-2022-40195

2022-09-2315:15:14
CWE-79
Patchstack
web.nvd.nist.gov
25
4
cve-2022-40195
authenticated
stored xss
pca predict plugin
wordpress
nvd

CVSS3

4.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N

EPSS

0.001

Percentile

19.4%

Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability in PCA Predict plugin <= 1.0.3 at WordPress.

Affected configurations

Nvd
Vulners
Node
loqateloqateRange1.0.3wordpress
VendorProductVersionCPE
loqateloqate*cpe:2.3:a:loqate:loqate:*:*:*:*:*:wordpress:*:*

CNA Affected

[
  {
    "product": "PCA Predict (WordPress plugin)",
    "vendor": "PCA Predict",
    "versions": [
      {
        "lessThanOrEqual": "1.0.3",
        "status": "affected",
        "version": "<= 1.0.3",
        "versionType": "custom"
      }
    ]
  }
]

Social References

More

CVSS3

4.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N

EPSS

0.001

Percentile

19.4%