CVE-2022-4782 Information

Description

The ClickFunnels WordPress plugin through 3.1.1 does not validate and escape one of its shortcode attributes which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attack.

Reference

https://wpscan.com/vulnerability/d3a0468a-8405-4b6c-800f-abd5ce5387b5

Share on: