CVE-2022-4973

MEDIUM EXPLOITED

WordPress < 6.0.2 - Authenticated Stored Cross-Site Scripting via the_meta() Function

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2022-4973 has been observed exploited in the wild (reported by VulnCheck KEV).

Description

WordPress Core, in versions up to 6.0.2, is vulnerable to Authenticated Stored Cross-Site Scripting that can be exploited by users with access to the WordPress post and page editor, typically consisting of Authors, Contributors, and Editors making it possible to inject arbitrary web scripts into posts and pages that execute if the the_meta(); function is called on that page.

Scores

CVSS v3 4.9
EPSS 0.0127
EPSS Percentile 79.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

VulnCheck KEV 2024-10-15
CWE
CWE-79
Status published
Products (26)
wordpress/wordpress < 6.0.2
WordPress Foundation/WordPress < 3.6.1
WordPress Foundation/WordPress 3.7 - 3.7.38
WordPress Foundation/WordPress 3.8 - 3.8.38
WordPress Foundation/WordPress 3.9 - 3.9.36
WordPress Foundation/WordPress 4.0 - 4.0.35
WordPress Foundation/WordPress 4.1 - 4.1.35
WordPress Foundation/WordPress 4.2 - 4.2.32
WordPress Foundation/WordPress 4.3 - 4.3.28
WordPress Foundation/WordPress 4.4 - 4.4.27
... and 16 more
Published Oct 16, 2024
Tracked Since Feb 18, 2026