cleantalk
Vulnerabilities and Security Researches

Themify Shortcodes, CVE-2022-4787

CVE, Research URL

CVE-2022-4787

Application

Themify Shortcodes

Published on
Jan 31, 2023
Research Description
Themify Shortcodes WordPress plugin before 2.0.8 does not validate and escape one of its shortcode attributes, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attack.
Affected versions
Min -, max 2.0.8.
Status
vulnerable