Headline
CVE-2022-33978: WordPress FontMeister plugin <= 1.08 - Reflected Cross-Site Scripting (XSS) vulnerability - Patchstack
Reflected Cross-Site Scripting (XSS) vulnerability FontMeister plugin <= 1.08 at WordPress.
Verified
Not fixed
6.1
CVSS 3.1 score Medium severity
Report
Monitoring Not reported to be exploited
Vulnerable versions
<= 1.08
PSID
39c9996f51b9
Classification
Cross Site Scripting (XSS)
OWASP Top 10
A7: Cross-Site Scripting (XSS)
Publicly disclosed
2022-09-23
Details
Reflected Cross-Site Scripting (XSS) vulnerability discovered by Tien Nguyen Anh (Patchstack Alliance) in WordPress FontMeister plugin (versions <= 1.08).
Solution
No patched version is available. No reply from the vendor.
References