VDB

CVE-2022-1961

CVE-2022-1961 PUBLISHED CVSS 5.5 MEDIUM

The Google Tag Manager for WordPress (GTM4WP) plugin is vulnerable to Stored Cross-Site Scripting due to insufficient escaping via the `gtm4wp-options[scroller-contentid]` parameter found in the `~/public/frontend.php` file which allowed attackers with administrative user access to inject arbitrary web scripts, in versions up to and including 1.15.1. This affects multi-site installations where unfiltered_html is disabled for administrators, and sites where unfiltered_html is disabled.

EPSS 1.12% · 64.7th percentile

Risk Scores

CVSS 3.1
5.5
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:N
EPSS Score
1.12%
64.7th percentile

Affected Products

VendorProductVersions
gtm4wpgoogle_tag_manager0
duracelltomiGTM4WP*

Timeline

  • Jun 13, 2022 CVE Published
  • Jun 14, 2022 EPSS Score
  • Aug 3, 2022 EPSS Score
  • Sep 20, 2022 EPSS Score
  • Dec 26, 2022 EPSS Score
  • Feb 13, 2023 EPSS Score
  • Mar 7, 2023 EPSS Score
  • Apr 2, 2023 EPSS Score
  • Jul 8, 2023 EPSS Score
  • Aug 26, 2023 EPSS Score
  • Oct 13, 2023 EPSS Score
  • Dec 1, 2023 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›