Vulnerability Description
The Bulk Edit and Create User Profiles WordPress plugin before 1.5.14 does not sanitise and escape the Users Login, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Wpsheeteditor | Bulk Edit And Create User Profiles - Wp Sheet Editor | < 1.5.14 |
Related Weaknesses (CWE)
References
- https://wpscan.com/vulnerability/75a9fd23-7fa9-4cb1-a55b-ec5deae5d6faExploitThird Party Advisory
- https://wpscan.com/vulnerability/75a9fd23-7fa9-4cb1-a55b-ec5deae5d6faExploitThird Party Advisory
FAQ
What is CVE-2022-1089?
CVE-2022-1089 is a vulnerability with a CVSS score of 4.8 (MEDIUM). The Bulk Edit and Create User Profiles WordPress plugin before 1.5.14 does not sanitise and escape the Users Login, which could allow high privilege users such as admin to perform Stored Cross-Site Sc...
How severe is CVE-2022-1089?
CVE-2022-1089 has been rated MEDIUM with a CVSS base score of 4.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-1089?
Check the references section above for vendor advisories and patch information. Affected products include: Wpsheeteditor Bulk Edit And Create User Profiles - Wp Sheet Editor.