CVE-2022-4946
CVSS 3.1 Score 5.4 of 10 (medium)
Details
Published Jun 5, 2023
Updated: Jan 8, 2025
CWE ID 601
Summary
CVE-2022-4946: This vulnerability affects the Frontend Post WordPress Plugin before version 2.8.5. It allows contributors, with a relatively low role, to add malicious shortcodes to pages or posts, resulting in unintended redirection of users to arbitrary domains. The plugin fails to validate an attribute within the shortcode, making it exploitable without requiring elevated privileges.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Vendors
- Accesspressthemes