ZeroHour

CVE-2022-4790

PoC
CVSS 3.1
5.4 medium
EPSS
<1%p39
Published
()
Modified
Description

The WP Google My Business Auto Publish WordPress plugin before 3.4 does not validate and escape one of its shortcode attributes, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attack.

Vendors
auto publish for google my business project
Products
auto publish for google my business
Ecosystems
WordPress
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.