NA

CVE-2022-3631

Published: 14/11/2022 Updated: 16/11/2022
CVSS v3 Base Score: 4.8 | Impact Score: 2.7 | Exploitability Score: 1.7
VMScore: 0

Vulnerability Summary

The OAuth Client by DigitialPixies WordPress plugin up to and including 1.1.0 does not sanitize and escapes some of its settings, which could allow high-privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example, in multisite setup).

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

digitialpixies oauth client