Lucene search

K
cvePatchstackCVE-2022-44736
HistoryNov 17, 2022 - 11:15 p.m.

CVE-2022-44736

2022-11-1723:15:24
CWE-79
Patchstack
web.nvd.nist.gov
27
5
cve-2022-44736
auth
admin+
stored
cross-site scripting
xss
vulnerability
chameleon plugin
wordpress

CVSS3

4.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N

EPSS

0.001

Percentile

22.7%

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Chameleon plugin <= 1.4.3 on WordPress.

Affected configurations

Nvd
Vulners
Node
chameleon_projectchameleonRange<1.4.4wordpress
VendorProductVersionCPE
chameleon_projectchameleon*cpe:2.3:a:chameleon_project:chameleon:*:*:*:*:*:wordpress:*:*

CNA Affected

[
  {
    "vendor": "Fahad Mahmood",
    "product": "Chameleon (WordPress plugin)",
    "versions": [
      {
        "version": "<= 1.4.3",
        "status": "affected",
        "lessThanOrEqual": "1.4.3",
        "versionType": "custom"
      }
    ]
  }
]

Social References

More

CVSS3

4.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N

EPSS

0.001

Percentile

22.7%

Related for CVE-2022-44736