VDB
CVE-2022-3840
CVE-2022-3840
PUBLISHED
CVSS 4.800000190734863 MEDIUM
The Login for Google Apps WordPress plugin before 3.4.5 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
EPSS 0.53% · 43.9th percentile
Risk Scores
CVSS 3.1
4.800000190734863
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
EPSS Score
0.53%
43.9th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Unknown | Login for Google Apps | 0 |
| wp-glogin | login_for_google_apps | 0 |
Timeline
- Dec 26, 2022 CVE Published
- Dec 27, 2022 EPSS Score
- Feb 7, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- May 1, 2023 EPSS Score
- Jun 12, 2023 EPSS Score
- Jul 24, 2023 EPSS Score
- Sep 3, 2023 EPSS Score
- Oct 15, 2023 EPSS Score
- Nov 26, 2023 EPSS Score
- Feb 17, 2024 EPSS Score
- Mar 30, 2024 EPSS Score