Vulnerability Description
The Mihdan: No External Links WordPress plugin before 5.0.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Mihdan\ | No External Links Project | < 5.0.2, mihdan\ |
Related Weaknesses (CWE)
References
- https://wpscan.com/vulnerability/bf476a3e-05ba-4b54-8a65-3d261ad5337bExploitThird Party Advisory
- https://wpscan.com/vulnerability/bf476a3e-05ba-4b54-8a65-3d261ad5337bExploitThird Party Advisory
FAQ
What is CVE-2022-1095?
CVE-2022-1095 is a vulnerability with a CVSS score of 4.8 (MEDIUM). The Mihdan: No External Links WordPress plugin before 5.0.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripti...
How severe is CVE-2022-1095?
CVE-2022-1095 has been rated MEDIUM with a CVSS base score of 4.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-1095?
Check the references section above for vendor advisories and patch information. Affected products include: Mihdan\ No External Links Project.