CVE-2022-0376 Information

Description

The User Meta WordPress plugin before 2.4.3 does not sanitise and escape the Form Name as well as Shared Field Labels before outputting them in the admin dashboard when editing a form which could allow high privilege users to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed

Reference

https://wpscan.com/vulnerability/a3ca2ed4-11ea-4d78-aa4c-4ed58f258932

Share on: