Lucene search

K
prionPRIOn knowledge basePRION:CVE-2022-3631
HistoryNov 14, 2022 - 3:15 p.m.

Cross site scripting

2022-11-1415:15:00
PRIOn knowledge base
www.prio-n.com
4
oauth client
digitalpixies
wordpress
stored cross-site scripting
settings
high-privilege users
admin
unfiltered_html
multisite setup

0.001 Low

EPSS

Percentile

24.8%

The OAuth Client by DigitialPixies WordPress plugin through 1.1.0 does not sanitize and escapes some of its settings, which could allow high-privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example, in multisite setup).

CPENameOperatorVersion
oauth_clientle1.1.0

0.001 Low

EPSS

Percentile

24.8%

Related for PRION:CVE-2022-3631