Vulnerability Description
The Taskbuilder WordPress plugin before 1.0.8 does not validate and sanitise task's attachments, which could allow any authenticated user (such as subscriber) creating a task to perform Stored Cross-Site Scripting by attaching a malicious SVG file
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Taskbuilder | Taskbuilder | < 1.0.8 |
Related Weaknesses (CWE)
References
- https://wpscan.com/vulnerability/524928d6-d4e9-4a2f-b410-46958da549d8ExploitThird Party Advisory
- https://wpscan.com/vulnerability/524928d6-d4e9-4a2f-b410-46958da549d8ExploitThird Party Advisory
FAQ
What is CVE-2022-3137?
CVE-2022-3137 is a vulnerability with a CVSS score of 5.4 (MEDIUM). The Taskbuilder WordPress plugin before 1.0.8 does not validate and sanitise task's attachments, which could allow any authenticated user (such as subscriber) creating a task to perform Stored Cross-S...
How severe is CVE-2022-3137?
CVE-2022-3137 has been rated MEDIUM with a CVSS base score of 5.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-3137?
Check the references section above for vendor advisories and patch information. Affected products include: Taskbuilder Taskbuilder.