ZeroHour

CVE-2022-3194

PoC
CVSS 3.1
5.4 medium
EPSS
<1%p41
Published
()
Modified
Description

The Dokan WordPress plugin before 3.6.4 allows vendors to inject arbitrary javascript in product reviews, which may allow them to run stored XSS attacks against other users like site administrators.

Vendors
dokan
Products
dokan
Ecosystems
WordPress
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.