CVE-2022-2941

MEDIUM

WP-UserOnline <= 2.88.0 - Authenticated Stored Cross-Site Scripting in Naming Conventions

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2022-2941. PoCs published by UnD3sc0n0c1d0.

AI-analyzed exploit summary This is a writeup describing a stored XSS vulnerability in the WordPress plugin WP-UserOnline version 2.88.0. The vulnerability allows authenticated attackers with administrative privileges to inject JavaScript code into the 'Naming Conventions' section, which executes when users access the injected page.

Description

The WP-UserOnline plugin for WordPress has multiple Stored Cross-Site Scripting vulnerabilities in versions up to, and including 2.88.0. This is due to the fact that all fields in the "Naming Conventions" section do not properly sanitize user input, nor escape it on output. This makes it possible for authenticated attackers, with administrative privileges, to inject JavaScript code into the setting that will execute whenever a user accesses the injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

Exploits (1)

exploitdb WRITEUP VERIFIED
by UnD3sc0n0c1d0 · textwebappsphp
https://www.exploit-db.com/exploits/51020

This is a writeup describing a stored XSS vulnerability in the WordPress plugin WP-UserOnline version 2.88.0. The vulnerability allows authenticated attackers with administrative privileges to inject JavaScript code into the 'Naming Conventions' section, which executes when users access the injected page.

Classification
Writeup 100%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target: WP-UserOnline 2.88.0
Auth required
Prerequisites: Authenticated access with administrative privileges · WP-UserOnline plugin version 2.88.0 installed and activated
MITRE ATT&CK
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Scores

CVSS v3 5.5
EPSS 0.0495
EPSS Percentile 91.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-79
Status published
Products (2)
gamerz/WP-UserOnline < 2.88.0
wp-useronline_project/wp-useronline < 2.88.1
Published Sep 06, 2022
Tracked Since Feb 18, 2026