VDB
CVE-2022-4470
CVE-2022-4470
PUBLISHED
CVSS 5.400000095367432 MEDIUM
The Widgets for Google Reviews WordPress plugin before 9.8 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.
EPSS 0.51% · 42.3th percentile
Risk Scores
CVSS 3.1
5.400000095367432
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
EPSS Score
0.51%
42.3th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| trustindex | widgets_for_google_reviews | 0 |
| Unknown | Widgets for Google Reviews | 0 |
Timeline
- Jan 30, 2023 CVE Published
- Jan 31, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Mar 13, 2023 EPSS Score
- Jun 2, 2023 EPSS Score
- Jul 12, 2023 EPSS Score
- Aug 22, 2023 EPSS Score
- Oct 1, 2023 EPSS Score
- Nov 11, 2023 EPSS Score
- Dec 21, 2023 EPSS Score
- Mar 11, 2024 EPSS Score
- Apr 21, 2024 EPSS Score