Description
WordPress Core, in versions up to 6.0.2, is vulnerable to Authenticated Stored Cross-Site Scripting that can be exploited by users with access to the WordPress post and page editor, typically consisting of Authors, Contributors, and Editors making it possible to inject arbitrary web scripts into posts and pages that execute if the the_meta(); function is called on that page.
INFO
Published Date :
2024-10-16T06:43:41.734Z
Last Modified :
2026-04-08T17:17:09.962Z
Source :
Wordfence
AFFECTED PRODUCTS
The following products are affected by CVE-2022-4973 vulnerability.
| Vendors | Products |
|---|---|
| Wordpress |
|
REFERENCES
Here, you will find a curated list of external links that provide in-depth information to CVE-2022-4973.
CVSS Vulnerability Scoring System
Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact