VDB

CVE-2022-3840

CVE-2022-3840 PUBLISHED CVSS 4.800000190734863 MEDIUM

The Login for Google Apps WordPress plugin before 3.4.5 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

EPSS 0.53% · 43.9th percentile

Risk Scores

CVSS 3.1
4.800000190734863
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
EPSS Score
0.53%
43.9th percentile

Affected Products

VendorProductVersions
UnknownLogin for Google Apps0
wp-gloginlogin_for_google_apps0

Timeline

  • Dec 26, 2022 CVE Published
  • Dec 27, 2022 EPSS Score
  • Feb 7, 2023 EPSS Score
  • Mar 7, 2023 EPSS Score
  • May 1, 2023 EPSS Score
  • Jun 12, 2023 EPSS Score
  • Jul 24, 2023 EPSS Score
  • Sep 3, 2023 EPSS Score
  • Oct 15, 2023 EPSS Score
  • Nov 26, 2023 EPSS Score
  • Feb 17, 2024 EPSS Score
  • Mar 30, 2024 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›