icon

We found results for “

CVE-2022-4512

Good to know:

icon

Date: February 13, 2023

The Better Font Awesome WordPress plugin before 2.0.4 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

Language: PHP

Severity Score

Severity Score

Weakness Type (CWE)

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CWE-79

Top Fix

icon

Upgrade Version

Upgrade to version mickey-kay/better-font-awesome - v2.0.0-beta4;mickey-kay/better-font-awesome - dev-bugfix/add-missing-files;mickey-kay/better-font-awesome - dev-feature/fa=-5;mickey-kay/better-font-awesome - v2.0.0-beta;mickey-kay/better-font-awesome-library - 1.4.1;mickey-kay/better-font-awesome-library - dev-bugfix/include-inline-v4-shim-css;mickey-kay/better-font-awesome-library - dev-npm-build-spec;mickey-kay/better-font-awesome-library - 2.0.3;mickey-kay/better-font-awesome-library - 1.0.3;mickey-kay/better-font-awesome-library - dev-feature/js-support;mickey-kay/better-font-awesome-library - dev-bugfix/escape-attrs;mickey-kay/better-font-awesome-library - dev-dependabot/npm_and_yarn/minimist-1.2.5;mickey-kay/better-font-awesome-library - 1.0.2;mickey-kay/better-font-awesome-library - no_fix

Learn More

CVSS v3.1

Base Score:
Attack Vector (AV): NETWORK
Attack Complexity (AC): LOW
Privileges Required (PR): LOW
User Interaction (UI): REQUIRED
Scope (S): CHANGED
Confidentiality (C): LOW
Integrity (I): LOW
Availability (A): NONE

Do you need more information?

Contact Us