ZeroHour

CVE-2022-0989

PoC
CVSS 3.1
7.5 high
EPSS
1%p67
Published
()
Modified
Description

An unprivileged user could use the functionality of the NS WooCommerce Watermark WordPress plugin through 2.11.3 to load images that hide malware for example from passing malicious domains to hide their trace, by making them pass through the vulnerable domain.

Vendors
nsthemes
Products
ns watermark for woocommerce
Ecosystems
WordPress, E-commerce
Weakness
CWE-80
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

In the news

No ingested article mentions this CVE yet.