Lucene search

K
cvelistWPScanCVELIST:CVE-2022-2171
HistoryAug 01, 2022 - 12:49 p.m.

CVE-2022-2171 Progressive License <= 1.1.0 - CSRF to Stored XSS

2022-08-0112:49:33
CWE-352
WPScan
www.cve.org
3
wordpress
csrf
stored xss
progressive license
security vulnerability

EPSS

0.001

Percentile

21.2%

The Progressive License WordPress plugin through 1.1.0 is lacking any CSRF check when saving its settings, which could allow attackers to make a logged in admin change them. Furthermore, as the plugin allows arbitrary HTML to be inserted in one of the settings, this could lead to Stored XSS issue which will be triggered in the frontend as well.

CNA Affected

[
  {
    "product": "Progressive License",
    "vendor": "Unknown",
    "versions": [
      {
        "lessThanOrEqual": "1.1.0",
        "status": "affected",
        "version": "1.1.0",
        "versionType": "custom"
      }
    ]
  }
]

EPSS

0.001

Percentile

21.2%

Related for CVELIST:CVE-2022-2171