VDB

CVE-2022-4470

CVE-2022-4470 PUBLISHED CVSS 5.400000095367432 MEDIUM

The Widgets for Google Reviews WordPress plugin before 9.8 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.

EPSS 0.51% · 42.3th percentile

Risk Scores

CVSS 3.1
5.400000095367432
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
EPSS Score
0.51%
42.3th percentile

Affected Products

VendorProductVersions
trustindexwidgets_for_google_reviews0
UnknownWidgets for Google Reviews0

Timeline

  • Jan 30, 2023 CVE Published
  • Jan 31, 2023 EPSS Score
  • Mar 7, 2023 EPSS Score
  • Mar 13, 2023 EPSS Score
  • Jun 2, 2023 EPSS Score
  • Jul 12, 2023 EPSS Score
  • Aug 22, 2023 EPSS Score
  • Oct 1, 2023 EPSS Score
  • Nov 11, 2023 EPSS Score
  • Dec 21, 2023 EPSS Score
  • Mar 11, 2024 EPSS Score
  • Apr 21, 2024 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›