Files
CVEs-PoC/2022/CVE-2022-4792.md
T
2024-05-25 21:48:12 +02:00

789 B

CVE-2022-4792

Description

The News & Blog Designer Pack WordPress plugin before 3.3 does not validate and escape one of its shortcode attributes, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attack.

POC

Reference

Github

No PoCs found on GitHub currently.