VDB

CVE-2022-1772

CVE-2022-1772 PUBLISHED CVSS 4.800000190734863 MEDIUM

The Google Places Reviews WordPress plugin before 2.0.0 does not properly escape its Google API key setting, which is reflected on the site's administration panel. A malicious administrator could abuse this bug, in a multisite WordPress configuration, to trick super-administrators into viewing the booby-trapped payload and taking over their account.

EPSS 0.75% · 53.5th percentile

Risk Scores

CVSS 3.1
4.800000190734863
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
EPSS Score
0.75%
53.5th percentile

Affected Products

VendorProductVersions
UnknownGoogle Places Reviews2.0.0
google_places_reviews_projectgoogle_places_reviews0

Timeline

  • Jun 13, 2022 CVE Published
  • Jun 14, 2022 EPSS Score
  • Aug 3, 2022 EPSS Score
  • Nov 8, 2022 EPSS Score
  • Dec 26, 2022 EPSS Score
  • Feb 13, 2023 EPSS Score
  • Mar 7, 2023 EPSS Score
  • May 21, 2023 EPSS Score
  • Jul 8, 2023 EPSS Score
  • Aug 26, 2023 EPSS Score
  • Oct 13, 2023 EPSS Score
  • Jan 18, 2024 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›