VDB

CVE-2022-1994

CVE-2022-1994 PUBLISHED CVSS 4.800000190734863 MEDIUM

The Login With OTP Over SMS, Email, WhatsApp and Google Authenticator WordPress plugin before 1.0.8 does not escape its settings, allowing high privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html is disallowed

EPSS 0.59% · 46.8th percentile

Risk Scores

CVSS 3.1
4.800000190734863
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
EPSS Score
0.59%
46.8th percentile

Affected Products

VendorProductVersions
UnknownLogin With OTP Over SMS, Email, WhatsApp and Google Authenticator1.0.8
miniorangelogin_with_otp_over_sms\,_email\,_whatsapp_and_google_authenticator0

Timeline

  • Jun 27, 2022 CVE Published
  • Jun 28, 2022 EPSS Score
  • Aug 16, 2022 EPSS Score
  • Oct 3, 2022 EPSS Score
  • Jan 7, 2023 EPSS Score
  • Feb 25, 2023 EPSS Score
  • Mar 7, 2023 EPSS Score
  • Apr 14, 2023 EPSS Score
  • Jun 1, 2023 EPSS Score
  • Jul 19, 2023 EPSS Score
  • Oct 23, 2023 EPSS Score
  • Dec 10, 2023 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›