Wordfence Security – Firewall & Malware Scan <= 7.6.0 - Authenticated (Admin+) Stored Cross-Site Scripting
Published Sep 23, 2022
4.8
MEDIUMCVSS 3.1
EPSS 0.81%
Description
The Wordfence Security – Firewall & Malware Scan plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to and including 7.6.0 via a setting on the options page due to insufficient escaping on the stored value. This makes it possible for authenticated users, with administrative privileges, to inject malicious web scripts into the setting that executes whenever a user accesses a page displaying the affected setting on sites running a vulnerable version.
Affected products
- Vendor Mmaunder Product Wordfence Security – Firewall, Malware Scan, and Login Security Defaultunaffected
Affected
- ≥ 0, ≤ 7.6.0
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Mmaunder | Wordfence Security – Firewall, Malware Scan, and Login Security | unaffected | Affected
|
- ≤ 7.6.0
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (5)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-42570 Advisory
- https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=2780937%40wordfence&new=2780937%40wordfence&sfp_email=&sfph_mail= PatchThird Party Advisory
- https://wordpress.org/plugins/wordfence/#developers Release Notes
- https://www.wordfence.com/threat-intel/vulnerabilities/id/833eb481-4fb4-432e-8e93-3f497ccbf1eb?source=cve
- https://www.wordfence.com/vulnerability-advisories/#CVE-2022-3144 Third Party Advisory
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
No data
Red Hat
No data
GitHub
No data