4.8
CVSSv3

CVE-2022-3207

Published: 10/10/2022 Updated: 12/10/2022
CVSS v3 Base Score: 4.8 | Impact Score: 2.7 | Exploitability Score: 1.7

Vulnerability Summary

The Simple File List WordPress plugin prior to 4.4.12 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

Most Upvoted Vulmon Research Post

There is no Researcher post for this vulnerability
Would you like to share something about it? Sign up now to share your knowledge with the community.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

simplefilelist simple-file-list

Github Repositories

CVE-2022-3207 The Simple File List WordPress plugin before 4412 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup) authentication complexity vector not available not available not ava