CVE-2022-3904
MEDIUMMonsterinsights < 8.9.1 - XSS
Title source: ruleDescription
The MonsterInsights WordPress plugin before 8.9.1 does not sanitize or escape page titles in the top posts/pages section, allowing an unauthenticated attacker to inject arbitrary web scripts into the titles by spoofing requests to google analytics.
Exploits (1)
Scores
CVSS v3
6.1
EPSS
0.4132
EPSS Percentile
97.3%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Classification
CWE
CWE-79
Status
published
Affected Products (1)
monsterinsights/monsterinsights
< 8.9.1
Timeline
Published
Jan 16, 2023
Tracked Since
Feb 18, 2026