Headline
CVE-2022-42460: WordPress Traffic Manager plugin <= 1.4.5 - Broken Access Control vulnerability leading to Stored Cross-Site Scripting (XSS) - Patchstack
Broken Access Control vulnerability leading to Stored Cross-Site Scripting (XSS) in Traffic Manager plugin <= 1.4.5 on WordPress.
Verified
Not fixed
6.5
CVSS 3.1 score Medium severity
Report
Monitoring Not reported to be exploited
Vulnerable versions
<= 1.4.5
PSID
e058716fc77e
Classification
Multiple Vulnerabilities
OWASP Top 10
A5: Broken Access Control
Required privilege
Requires subscriber or higher role user authentication.
Publicly disclosed
2022-10-24
Details
Broken Access Control vulnerability leading to Stored Cross-Site Scripting (XSS) discovered by Lana Codes (Patchstack Alliance) in the WordPress Traffic Manager plugin (versions <= 1.4.5).
Solution
Deactivate and delete. This plugin has been closed as of September 19, 2022 and is not available for download. This closure is temporary, pending a full review.
References