CVE-2022-4171

MEDIUM

WordPress demon image annotation <5.0 - Info Disclosure

Title source: llm
STIX 2.1

Description

The demon image annotation plugin for WordPress is vulnerable to improper input validation in versions up to, and including 5.0. This is due to the plugin improperly validating the number of characters supplied during an annotation despite there being a setting to limit the number characters input. This means that unauthenticated attackers can bypass the length restrictions and input more characters than allowed via the settings.

Scores

CVSS v3 6.5
EPSS 0.0049
EPSS Percentile 65.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-1284
Status published
Products (2)
demonisblack/demon image annotation < 5.0
superwhite/demon_image_annotation < 5.0
Published Dec 13, 2022
Tracked Since Feb 18, 2026