Security
Headlines
HeadlinesLatestCVEs

Headline

CVE-2022-42460: WordPress Traffic Manager plugin <= 1.4.5 - Broken Access Control vulnerability leading to Stored Cross-Site Scripting (XSS) - Patchstack

Broken Access Control vulnerability leading to Stored Cross-Site Scripting (XSS) in Traffic Manager plugin <= 1.4.5 on WordPress.

CVE
#xss#vulnerability#wordpress#auth

Verified

Not fixed

6.5

CVSS 3.1 score Medium severity

Report

Monitoring Not reported to be exploited

Vulnerable versions

<= 1.4.5

PSID

e058716fc77e

Classification

Multiple Vulnerabilities

OWASP Top 10

A5: Broken Access Control

Required privilege

Requires subscriber or higher role user authentication.

Publicly disclosed

2022-10-24

Details

Broken Access Control vulnerability leading to Stored Cross-Site Scripting (XSS) discovered by Lana Codes (Patchstack Alliance) in the WordPress Traffic Manager plugin (versions <= 1.4.5).

Solution

Deactivate and delete. This plugin has been closed as of September 19, 2022 and is not available for download. This closure is temporary, pending a full review.

References

CVE: Latest News

CVE-2023-50976: Transactions API Authorization by oleiman · Pull Request #14969 · redpanda-data/redpanda
CVE-2023-6905
CVE-2023-6903
CVE-2023-6904
CVE-2023-3907