Headline
CVE-2022-44590: WordPress Simple Video Embedder plugin <= 2.2 - Auth. Stored Cross-Site Scripting (XSS) vulnerability - Patchstack
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in James Lao’s Simple Video Embedder plugin <= 2.2 on WordPress.
Verified
Not fixed
5.4
CVSS 3.1 score Medium severity
Report
Monitoring Not reported to be exploited
Software
Simple Video Embedder
Vulnerable versions
<= 2.2
PSID
0ab080724815
Classification
Cross Site Scripting (XSS)
OWASP Top 10
A7: Cross-Site Scripting (XSS)
Required privilege
Requires contributor or higher role user authentication.
Publicly disclosed
2022-11-09
Details
Auth. Stored Cross-Site Scripting (XSS) vulnerability discovered by thiennv (Patchstack Alliance) in WordPress Simple Video Embedder plugin (versions <= 2.2).
Solution
Deactivate and delete. This plugin has been closed as of November 8, 2022 and is not available for download. This closure is temporary, pending a full review.
References